CVE-2012-10030 Details
Description
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path. These conditions enable attackers to upload executable payloads and .mof files to locations such as system32 and wbem\mof, where Windows Management Instrumentation (WMI) automatically processes and executes them. This results in remote code execution with SYSTEM-level privileges, without requiring user interaction.
A vulnerability exists in FreeFloat FTP Server that allows unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server's design flaws include accepting empty credentials, defaulting user access to the root of the C: drive, and lacking restrictions on file types or destination paths. These vulnerabilities enable attackers to upload executable files and .mof files to locations such as system32 and wbem\mof, where they are automatically processed and executed by Windows Management Instrumentation (WMI). This exploitation leads to remote code execution with SYSTEM-level privileges, without requiring user interaction.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freefloat freefloat ftp server | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| Aug 6, 2025 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | New CVE Received | [email protected] |