Vulnerability record · CVE-2014-3791 · published 20 May 2014
CVE-2014-3791: Easy File Sharing Web Server cookie buffer overflow
Efssoft · Easy File Sharing Web Server
Easy File Sharing (EFS) Web Server 6.8 has a stack-based buffer overflow reachable through a long string in the cookie UserID parameter sent to vfolder.ghp. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code on the server.
Description
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has a CVSS 2.0 score of 10, and public exploit code plus very high EPSS make active exploitation likely.
What it is
Easy File Sharing (EFS) Web Server 6.8 has a stack-based buffer overflow reachable through a long string in the cookie UserID parameter sent to vfolder.ghp. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code on the server.
Impact
Successful exploitation gives the attacker remote code execution in the context of the web server process, which typically runs with the privileges of the service account. This can lead to full compromise of the host and any data it serves.
Attack surface
The flaw is reached over the network via an HTTP request to vfolder.ghp with an oversized UserID cookie value. No authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
Multiple public exploit references exist (Exploit-DB, Packet Storm, and a vendor blog), and EPSS is 0.787 with a 0.99569 percentile, indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Apply the vendor patch or upgrade Easy File Sharing Web Server beyond version 6.8 if an update is available.
- If no patch exists, restrict network access to the EFS web service to trusted hosts and block external exposure.
- Run the service under a low-privilege account and isolate it from sensitive data and internal networks.
- Deploy a WAF or reverse proxy rule that rejects oversized or malformed UserID cookie values.
- Monitor vendor advisories for a fixed release and retire the affected version if support has ended.
Detection
- Inspect web server logs for requests to vfolder.ghp with unusually long UserID cookie values.
- Alert on crashes or restarts of the EFS web server process that coincide with HTTP requests.
- Use network monitoring to flag HTTP requests containing oversized cookie headers to the EFS service.
- Correlate exploit-db or Packet Storm payload signatures against inbound traffic to the EFS port.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3791 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3791), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.