EXPOSURES › CVE-2024-4040
CVE-2024-4040
HIGH ⌖ ON CISA KEV · EXPLOITEDCrushFTP's VFS sandbox escape vulnerability (CVE-2024-4040) allows remote attackers to bypass sandbox restrictions and execute arbitrary code.
This sandbox escape enables remote attackers to execute arbitrary code within the CrushFTP virtual file system, bypassing security controls critical for FedRAMP and NIST 800-171 compliance. DIB organizations must immediately patch or disable CrushFTP to prevent unauthorized code execution and potential data exfiltration.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a failure to patch a known security flaw promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).