EXPOSURES › CVE-2014-6287
CVE-2014-6287
HIGH ⌖ ON CISA KEV · EXPLOITEDRejetto HTTP File Server (HFS) suffered a remote code execution vulnerability that allowed attackers to execute arbitrary programs on affected systems.
The findMacroMarker function in parserLib.pas of Rejetto HTTP File Server (HFS) allowed remote attackers to execute arbitrary programs, enabling full system compromise. DIB organizations must ensure all HFS instances are patched to version 3.2.1 or later, as this vulnerability is actively exploited in the wild and poses a severe risk to network integrity and compliance with CMMC/NIST 800-171 requirements.
Shame score — The vulnerability was actively exploited in the wild and allowed remote code execution, representing a severe and avoidable security failure that could lead to full system compromise and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.