ntpd is usually run as a daemon, which is run as root, and if you can overflow a buffer somewhere, given you know the architecture and platform (arm, raspberry pi), and don't have data execution prevention, you can inject assembly instructions and jump a function pointer like any other stack overflow.
Then you have arbitrary code execution as ntpd. Unless you have apparmor, or some other MAC.