Vulnerability record · CVE-2004-2111 · published 31 December 2004
CVE-2004-2111: Serv-U FTP Server site chmod stack buffer overflow
Solarwinds · Serv U File Server
Serv-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can issue FTP commands can overwrite stack memory and potentially execute arbitrary code on the server.
Description
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
AV:N/AC:M/Au:S/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a CVSS 2.0 score of 8.5 and very high EPSS, but exploitation requires some authentication and the product is a legacy version.
What it is
Serv-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can issue FTP commands can overwrite stack memory and potentially execute arbitrary code on the server.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the Serv-U service, typically SYSTEM on Windows, leading to full host compromise. Even without code execution, the overflow can crash the service.
Attack surface
Reached over the network through the FTP service by sending a crafted site chmod command with an oversized filename. The CVSS vector (AV:N/AC:M/Au:S) indicates network access with some complexity and that some level of authentication or privilege is required, so valid FTP credentials are likely needed.
Exploitation
Public exploit references are tagged on Bugtraq and SecurityFocus, and EPSS is very high (0.86867, 99.7th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.
What to do
- Upgrade Serv-U FTP Server to version 4.2 or later, which fixes the overflow.
- If upgrade is not possible, restrict FTP access to trusted networks and disable or block the site chmod command.
- Enforce strong, unique FTP credentials and least-privilege accounts to limit who can reach the vulnerable command.
- Run the FTP service under a low-privilege account rather than SYSTEM to reduce the impact of code execution.
- Monitor vendor advisories for this legacy product and plan migration off end-of-life versions.
Detection
- Inspect FTP command logs for site chmod requests containing unusually long filenames or non-printable bytes.
- Alert on Serv-U service crashes or restarts, which may indicate a failed overflow attempt.
- Monitor for unexpected child processes or command shells spawned by the Serv-U service process.
- Use network IDS signatures for oversized FTP command arguments targeting the site chmod verb.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-2111 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-2111), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.