Vulnerability Description
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Progress | Ws Ftp Server | < 8.7.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-UnauthenticExploitThird Party AdvisoryVDB Entry
- https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044Third Party Advisory
- https://censys.com/cve-2023-40044/Third Party Advisory
- https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-SeVendor Advisory
- https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iiExploitThird Party Advisory
- https://www.progress.com/ws_ftpProduct
- https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_fBroken LinkThird Party Advisory
- https://www.theregister.com/2023/10/02/ws_ftp_update/Press/Media CoverageThird Party Advisory
- http://packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-UnauthenticExploitThird Party AdvisoryVDB Entry
- https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044Third Party Advisory
- https://censys.com/cve-2023-40044/Third Party Advisory
- https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-SeVendor Advisory
- https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iiExploitThird Party Advisory
- https://www.progress.com/ws_ftpProduct
- https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_fBroken LinkThird Party Advisory
FAQ
What is CVE-2023-40044?
CVE-2023-40044 is a vulnerability with a CVSS score of 10.0 (CRITICAL). In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the und...
How severe is CVE-2023-40044?
CVE-2023-40044 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-40044?
Check the references section above for vendor advisories and patch information. Affected products include: Progress Ws Ftp Server.