Vulnerability record · CVE-2017-6465 · published 10 March 2017
CVE-2017-6465: FTPShell Client PWD response buffer overflow allows remote code execution
Ftpshell · Ftpshell Client
FTPShell Client 6.53 sends a PWD command on connect and does not validate the length of the server's response, causing a stack buffer overflow (CWE-119). A malicious or compromised FTP server can therefore execute code on the connecting client, which matters because the client is the victim and the trigger is routine connection behavior.
Description
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.8 with public exploit code and very high EPSS, but no KEV listing and the flaw is in a legacy client, so it is high rather than critical for most environments.
What it is
FTPShell Client 6.53 sends a PWD command on connect and does not validate the length of the server's response, causing a stack buffer overflow (CWE-119). A malicious or compromised FTP server can therefore execute code on the connecting client, which matters because the client is the victim and the trigger is routine connection behavior.
Impact
An attacker controlling the FTP server gains remote code execution in the context of the FTPShell Client process on the victim's machine. That allows arbitrary code, data theft or further host compromise without any action by the user beyond connecting.
Attack surface
Reached over the network via the FTP protocol: the client connects to an attacker-controlled or compromised FTP server, which returns an oversized PWD response. No authentication to the client is required and no user interaction beyond initiating the connection; CVSS vector is AV:N/AC:L/PR:N/UI:N.
Exploitation
Public exploit code exists (Exploit-DB 41511 and Packet Storm advisory), and EPSS is 0.503 (98.9th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Upgrade FTPShell Client to a version later than 6.53 if the vendor has released a fix; the record does not name a fixed version, so verify with the vendor.
- If no patch is available, stop using FTPShell Client 6.53 and replace it with a maintained FTP client.
- Restrict client connections to trusted, known FTP servers and block outbound FTP to untrusted hosts at the perimeter.
- Where FTPShell must remain, isolate it in a low-privilege environment and monitor for crashes or unexpected child processes.
Detection
- Monitor FTPShell Client for crash events or access violations on connect, which may indicate an oversized PWD response.
- Alert on outbound FTP connections from hosts running FTPShell Client to servers outside an approved allowlist.
- Hunt for unexpected child processes or network connections spawned by the FTPShell Client process.
- Review proxy or firewall logs for FTP sessions to newly seen or untrusted server addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/141456/FTPShell-Client-6.53-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96570 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41511/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/141456/FTPShell-Client-6.53-Buffer-Overflow.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/96570 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41511/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-6465 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6465), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.