Skip to content
COOEY

EXPOSURES › CVE-2023-40044

CVE-2023-40044

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-40044 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Progress WS_FTP Server's Ad Hoc Transfer module allows authenticated attackers to execute remote commands via deserialization of untrusted data.

An authenticated attacker can exploit this deserialization vulnerability to execute arbitrary commands on the underlying operating system, enabling remote code execution. DIB organizations must patch this critical flaw immediately, as it is actively exploited in the wild and linked to ransomware campaigns, posing severe compliance and operational risks.

Shame score — A critical, actively exploited vulnerability in a widely deployed file transfer server that enables remote code execution and is linked to ransomware, representing a severe and avoidable failure in vendor security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.