EXPOSURES › CVE-2023-40044
CVE-2023-40044
CRITICAL ⌖ ON CISA KEV · EXPLOITEDProgress WS_FTP Server's Ad Hoc Transfer module allows authenticated attackers to execute remote commands via deserialization of untrusted data.
An authenticated attacker can exploit this deserialization vulnerability to execute arbitrary commands on the underlying operating system, enabling remote code execution. DIB organizations must patch this critical flaw immediately, as it is actively exploited in the wild and linked to ransomware campaigns, posing severe compliance and operational risks.
Shame score — A critical, actively exploited vulnerability in a widely deployed file transfer server that enables remote code execution and is linked to ransomware, representing a severe and avoidable failure in vendor security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.