QID 38908

Date Published: 2023-07-28

QID 38908: Microsoft Windows File Transfer Protocol (FTP) Denial of Service (DoS) Vulnerability

A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.

To exploit the vulnerability, an unauthenticated attacker could send specially crafted packets to a Windows computer that is processing connections on TCP port 21. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable FTP server by checking the banner of FTP server.

Successful exploitation of the vulnerability may result in Denial of Service attacks.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to apply the patches released by Microsoft. For more information please refer to MSRC Update Guide

    CVEs related to QID 38908

    Software Advisories
    Advisory ID Software Component Link
    CVE-2018-8206 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8206