Skip to content
COOEY

EXPOSURES › CVE-2024-4040

CVE-2024-4040

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4040 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildransomwareunpatchedrce

CrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code.

This sandbox escape enables remote attackers to execute arbitrary code within the CrushFTP virtual file system, bypassing security controls critical for FedRAMP and NIST 800-171 compliance. DIB organizations must immediately patch or disable CrushFTP to prevent unauthorized code execution and potential data exfiltration.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a failure to patch a known security flaw promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.