← Vulnerability feed

Vulnerability record · CVE-2015-7768 · published 9 October 2015

CVE-2015-7768: Konica Minolta FTP Utility CWD command buffer overflow

Konicaminolta · Ftp Utility

Konica Minolta FTP Utility 1.0 contains a buffer overflow reachable through a long CWD command. A remote attacker can overwrite memory and execute arbitrary code on the host running the FTP server. The flaw matters because the utility is a network-facing service and public exploit code exists.

7.5 CVSS 2.0 High EPSS 63% · top 0.8% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the product is a legacy niche FTP utility and not in KEV.

What it is

Konica Minolta FTP Utility 1.0 contains a buffer overflow reachable through a long CWD command. A remote attacker can overwrite memory and execute arbitrary code on the host running the FTP server. The flaw matters because the utility is a network-facing service and public exploit code exists.

Impact

An attacker gains remote code execution in the context of the FTP Utility process, which can lead to full compromise of the Windows host. No privilege escalation beyond the service account is described in the record.

Attack surface

Reached over the network via the FTP service on the host running Konica Minolta FTP Utility 1.0. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required, though one reference title labels a variant as post-auth; the record does not resolve this conflict.

Exploitation

Not listed in CISA KEV, but EPSS is 0.63209 (99.2nd percentile) and multiple references are tagged Exploit, including Packet Storm, Exploit-DB and a Rapid7 Metasploit module, indicating public exploit code is available.

What to do

  • Patch or upgrade Konica Minolta FTP Utility; if no fixed version exists, retire or replace the product.
  • Remove the FTP service from internet exposure and restrict access to trusted management networks.
  • Block or filter FTP traffic at the perimeter and segment hosts running the utility.
  • Run the service under a low-privilege account to limit post-exploitation impact.
  • Monitor vendor advisories for a supported replacement or fix.

Detection

  • Inspect FTP server logs for abnormally long CWD commands or malformed FTP command sequences.
  • Alert on crashes or restarts of the FTP Utility process on Windows hosts.
  • Hunt for unexpected child processes or network connections spawned by the FTP service process.
  • Use IDS/IPS signatures for known Konica Minolta FTP Utility CWD overflow exploits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7768 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2020-37068Konicaminolta ftp utility classic buffer overflow vulnerabilityKonica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Atta…EPSS 0.61%8.7CVE-2020-37069Konicaminolta ftp utility classic buffer overflow vulnerabilityKonica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Atta…EPSS 0.61%7.8CVE-2015-7603Konica Minolta FTP Utility directory traversal via RETR commandKonica Minolta FTP Utility 1.0 contains a directory traversal flaw (CWE-22) that lets a remote attacker read arbitrary files by supplying a ..\ seque…EPSS 61%analysed7.5CVE-2015-7767Konicaminolta ftp utility memory buffer overflow vulnerabilityBuffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) …EPSS 4.7%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2015-7768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.