Vulnerability record · CVE-2014-9295 · published 20 December 2014
CVE-2014-9295: NTP ntpd stack buffer overflows allow remote code execution
Ntp · Ntp
NTP before 4.2.8 contains multiple stack-based buffer overflows in ntpd, reachable through crafted packets in the crypto_recv (Autokey), ctl_putdata, and configure functions. Because ntpd typically runs with elevated privileges and is reachable over the network, a successful overflow can lead to remote code execution on the host.
Description
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution in a widely deployed network service with public exploit references and very high EPSS, though not listed in KEV.
What it is
NTP before 4.2.8 contains multiple stack-based buffer overflows in ntpd, reachable through crafted packets in the crypto_recv (Autokey), ctl_putdata, and configure functions. Because ntpd typically runs with elevated privileges and is reachable over the network, a successful overflow can lead to remote code execution on the host.
Impact
A remote attacker can corrupt stack memory and potentially execute arbitrary code with the privileges of the ntpd process, which is often root. This can lead to full host compromise or service disruption.
Attack surface
The flaw is reached over the network via crafted NTP packets; the CVSS vector AV:N/AC:L/Au:N indicates no authentication or user interaction is required. The Autokey path specifically requires that feature to be enabled, while the ctl_putdata and configure paths relate to control and configuration handling.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.79069, 99.577th percentile) and several references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade ntpd to NTP 4.2.8 or later, or apply the vendor patch for your distribution.
- If Autokey is not required, disable it to remove the crypto_recv attack path.
- Restrict network access to NTP ports (UDP 123 and control/query ports) to trusted sources only.
- Run ntpd with the least privileges possible and isolate it from sensitive systems.
- Monitor vendor advisories (Red Hat, SUSE, Oracle, HPE, etc.) and apply their updated packages.
Detection
- Inspect ntpd logs for crashes, restarts, or abnormal termination that may indicate a buffer overflow attempt.
- Monitor network traffic for malformed or unusually large NTP packets, especially to control/query and Autokey-related ports.
- Use host-based detection to watch for unexpected child processes or code execution originating from the ntpd process.
- Check for known exploit signatures against NTP traffic if your IDS/IPS supports them.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9295 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9295), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.