Skip to content
COOEY

EXPOSURES › CVE-2023-0669

CVE-2023-0669

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-0669 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Fortra GoAnywhere MFT suffered a pre-authentication remote code execution vulnerability due to deserializing attacker-controlled objects in the License Response Servlet.

The vulnerability allowed remote attackers to execute arbitrary code without authentication, enabling ransomware deployment and data exfiltration. DIB organizations must patch this critical flaw immediately and verify their MFT solutions for similar deserialization risks, as it directly impacts compliance with NIST 800-171 requirements for system integrity and access control.

Shame score — A pre-authentication RCE in a widely deployed MFT product linked to ransomware attacks demonstrates severe negligence and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.