CVE-2025-5196 Overview
CVE-2025-5196 affects Wing FTP Server versions up to and including 7.4.3. The vulnerability resides in the Lua Admin Console component and enables execution with unnecessary privileges [CWE-250]. Authenticated administrators can leverage the console to run code inheriting the elevated privileges of the Wing FTP service process, which typically runs as SYSTEM on Windows or root on Linux.
The vendor disputes the classification, stating that the system administrator role in Wing FTP already holds full permissions. Wing FTP recommends running the service as a normal user rather than SYSTEM or root to reduce impact.
Critical Impact
Authenticated administrators can execute Lua code through the admin console with the privileges of the host service account, resulting in full host compromise when the service runs as SYSTEM or root.
Affected Products
- Wing FTP Server versions up to and including 7.4.3
- Wing FTP Server deployments running the service as SYSTEM (Windows) or root (Linux)
- Wing FTP Server Lua Admin Console component
Discovery Timeline
- 2025-05-26 - CVE-2025-5196 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-5196
Vulnerability Analysis
Wing FTP Server exposes a Lua Admin Console that allows administrators to run Lua scripts against the running server. The console executes those scripts within the Wing FTP service process. When the service runs with the default SYSTEM or root account, any Lua code executed through the console inherits those privileges.
This behavior maps to CWE-250, Execution with Unnecessary Privileges. The admin console does not drop privileges before invoking user-supplied scripts. Administrative operations that only require file transfer or user management occur under the same high-privilege context used for the underlying service.
The attack requires network access and valid administrator credentials. Attack complexity is high, but successful exploitation yields high confidentiality, integrity, and availability impact on the host operating system, not just the FTP service.
Root Cause
The root cause is a privilege separation gap between the FTP service and its scripting interface. The Lua Admin Console does not sandbox script execution or reduce privileges before running administrator-supplied Lua code. Combined with default installation guidance that runs the service under a high-privilege account, this allows privileged host operations from what should be an application-layer administrative surface.
Attack Vector
An attacker must first obtain valid Wing FTP administrator credentials. This may occur through credential reuse, phishing, weak password policies, or through a separate authentication vulnerability. After authenticating to the admin console, the attacker submits Lua code that invokes operating system functions such as os.execute or file I/O primitives against arbitrary paths.
Because the code runs inside the Wing FTP service process, any commands issued through Lua execute with the service account's privileges. A proof-of-concept demonstrating authenticated remote code execution against version 7.4.4 is published on GitHub. Technical details are also indexed in VulDB entry 310279.
Detection Methods for CVE-2025-5196
Indicators of Compromise
- Unexpected child processes spawned by the Wing FTP service binary, including cmd.exe, powershell.exe, /bin/sh, or /bin/bash
- New or modified files under Wing FTP installation directories, including changes to Lua scripts stored on disk
- Administrator logins to the Wing FTP admin console from unusual source addresses or outside normal hours
- Outbound network connections initiated by the Wing FTP service process to attacker-controlled infrastructure
Detection Strategies
- Monitor process ancestry for the Wing FTP service and alert on any child process that is not a legitimate FTP helper
- Correlate Wing FTP admin console authentication events with subsequent host-level command execution
- Baseline Lua script content in the Wing FTP data directory and alert on unauthorized modifications
Monitoring Recommendations
- Forward Wing FTP admin console logs and Windows or Linux process telemetry to a centralized data lake for correlation
- Track successful and failed admin logins and alert on brute-force patterns against the admin console endpoint
- Enable file integrity monitoring on the Wing FTP installation directory and Lua script locations
How to Mitigate CVE-2025-5196
Immediate Actions Required
- Upgrade Wing FTP Server to version 7.4.4 or later, tracked on the Wing FTP Server history page
- Reconfigure the Wing FTP service to run under a dedicated, low-privilege service account rather than SYSTEM or root
- Rotate all Wing FTP administrator credentials and enforce strong, unique passwords
- Restrict network access to the admin console interface using firewall rules or a VPN
Patch Information
Wing FTP addresses this issue in version 7.4.4. Administrators should review the vendor's server history page for release notes and download the current release. The vendor also recommends running the service as a normal user rather than SYSTEM or root as a defense-in-depth measure regardless of version.
Workarounds
- Run the Wing FTP service under a non-privileged local user account with only the permissions required to access FTP data directories
- Limit admin console exposure to a management network segment and block internet-facing access
- Enforce multi-factor authentication and IP allow-listing for administrator accounts where supported
# Configuration example: run Wing FTP as a dedicated low-privilege user on Linux
sudo useradd --system --no-create-home --shell /usr/sbin/nologin wingftp
sudo chown -R wingftp:wingftp /opt/wingftp
sudo systemctl edit wingftp
# In the override file:
# [Service]
# User=wingftp
# Group=wingftp
sudo systemctl daemon-reload
sudo systemctl restart wingftp
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
