CVE-2019-16116
EnterpriseDT Complete FTP vulnerability analysis and mitigation

Overview

EnterpriseDT CompleteFTP Server versions prior to 12.1.3 contained a vulnerability that exposed sensitive information in the Bootstrap.log file, allowing attackers to obtain the administrator password hash. The vulnerability was discovered in September 2019 and was assigned CVE-2019-16116 (CVE Details, Rhino Labs).

Technical details

The vulnerability stems from information leakage in the Bootstrap.log file located in the Server subdirectory of the program installation directory. The log file, created during initial installation, contained SQL statements with the administrator's MD5 password hash and an encrypted passphrase used for authentication. This information could be used to gain unauthorized access to the CompleteFTP Manager interface with full administrative privileges (Rhino Labs). The vulnerability has a CVSS v3.1 base score of 4.3 (MEDIUM) with vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

The vulnerability allows attackers with read access to the program installation directory to obtain administrative credentials and gain full control of the CompleteFTP Server. Since the server runs by default with SYSTEM privileges, attackers could leverage built-in Process Triggers functionality to execute arbitrary code and escalate privileges on the Windows system (Rhino Labs).

Exploitability

The vulnerability is exploitable both locally and potentially remotely if a user is granted read access to the program installation directory. An attacker only needs access to the CompleteFTPManager.exe binary and the information leaked in the Bootstrap.log file to gain administrative access. A proof-of-concept exploit has been published demonstrating the complete attack chain (Rhino Labs).

Mitigation and workarounds

The vulnerability was patched in CompleteFTP Server version 12.1.3. Users should upgrade to this version or later to mitigate the risk. All versions 12.1.2 and below are considered vulnerable (Rhino Labs).

Additional resources


SourceThis report was generated using AI

Related EnterpriseDT Complete FTP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-2560CRITICAL9.1
  • EnterpriseDT Complete FTP logoEnterpriseDT Complete FTP
  • cpe:2.3:a:enterprisedt:completeftp_server
NoYesMar 29, 2023
CVE-2019-16864HIGH8.8
  • EnterpriseDT Complete FTP logoEnterpriseDT Complete FTP
  • cpe:2.3:a:enterprisedt:completeftp_server
NoYesFeb 14, 2022
CVE-2019-16116MEDIUM4.3
  • EnterpriseDT Complete FTP logoEnterpriseDT Complete FTP
  • cpe:2.3:a:enterprisedt:completeftp_server
NoYesOct 02, 2019

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management