Files
CVEs-PoC/2021/CVE-2021-41635.md
2025-09-29 21:09:30 +02:00

18 lines
728 B
Markdown

### [CVE-2021-41635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41635)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
### POC
#### Reference
- https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/
#### Github
No PoCs found on GitHub currently.