Vulnerability record · CVE-2008-2161 · published 12 May 2008
CVE-2008-2161: TFTP Server SP buffer overflow via long error packet
Tftp · Tftp Server Sp
TFTP Server SP versions 1.4 and 1.5 on Windows contain a buffer overflow that is triggered by a long TFTP error packet. A remote, unauthenticated attacker can send a crafted packet to corrupt memory and potentially execute arbitrary code. The record notes that some details come from third-party information, so the full scope of affected versions is uncertain.
Description
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a public exploit plus very high EPSS, though it is not in KEV and affects an old, likely uncommon product.
What it is
TFTP Server SP versions 1.4 and 1.5 on Windows contain a buffer overflow that is triggered by a long TFTP error packet. A remote, unauthenticated attacker can send a crafted packet to corrupt memory and potentially execute arbitrary code. The record notes that some details come from third-party information, so the full scope of affected versions is uncertain.
Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the TFTP service, which on Windows commonly runs as SYSTEM. That gives full control of the host, including data confidentiality, integrity, and availability.
Attack surface
The flaw is reachable over the network through the TFTP service (UDP port 69 by default) with no authentication required. No user interaction is needed; the attacker only needs to send a malformed error packet to the listening service.
Exploitation
No CISA KEV listing, but a public Exploit-DB entry (5563) exists and EPSS is 0.65284 (99.2nd percentile), indicating a high likelihood of exploitation activity. The record does not state whether exploitation has been observed in the wild.
What to do
- Patch or upgrade TFTP Server SP to a version later than 1.5, or replace it with a maintained TFTP implementation.
- If the service is not required, disable and uninstall it.
- Restrict TFTP access to trusted hosts and networks using host-based or network firewalls; do not expose UDP/69 to the internet.
- Run the TFTP service under a low-privilege account rather than SYSTEM.
- Monitor vendor advisories for updated guidance, since the record notes third-party sourcing.
Detection
- Inspect TFTP traffic for oversized or malformed error packets (opcode 5) that exceed expected length.
- Alert on TFTP service crashes or restarts, which may indicate a failed overflow attempt.
- Monitor for unexpected child processes or command execution originating from the TFTP service process.
- Review network logs for TFTP connections from untrusted or external source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2161), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.