Vulnerability record · CVE-2008-1611 · published 1 April 2008
CVE-2008-1611: TFTP Server SP 1.4 for Windows stack buffer overflow via long filename
Tftp Server · Winagents Tftp Server
TFTP Server SP 1.4 for Windows contains a stack-based buffer overflow (CWE-119) triggered by a long filename in a read or write request. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The record does not list affected version ranges beyond the named 1.4 release.
Description
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network-reachable, unauthenticated code execution potential and high EPSS, though no KEV listing.
What it is
TFTP Server SP 1.4 for Windows contains a stack-based buffer overflow (CWE-119) triggered by a long filename in a read or write request. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The record does not list affected version ranges beyond the named 1.4 release.
Impact
An attacker can cause a denial of service against the TFTP service and, given the overflow is stack-based and remotely reachable, may achieve arbitrary code execution in the context of the TFTP server process.
Attack surface
Reached over the network via the TFTP service (UDP port 69) by sending a crafted read or write request with an oversized filename. No authentication or user interaction is required, per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.676 probability, 99.3rd percentile) and public exploit references are present, including an Offensive Security PoC and an Exploit-DB entry.
What to do
- Patch or upgrade TFTP Server SP to a fixed release; if no fix exists, retire or replace the product.
- Disable the TFTP service where it is not strictly required.
- Restrict UDP/69 access to trusted hosts via firewall or ACLs.
- Run the TFTP service under a low-privilege account and isolate it from sensitive networks.
- Monitor vendor advisories for an updated build since the record does not name a patched version.
Detection
- Inspect TFTP read/write request packets for abnormally long filename fields.
- Alert on TFTP service crashes or restarts on hosts running TFTP Server SP.
- Monitor for unexpected child processes or outbound connections spawned by the TFTP service process.
- Review network logs for TFTP traffic from untrusted or unexpected source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1611 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.