Critical RCE Vulnerability in WS_FTP Server Disclosed

Critical RCE Vulnerability in WS_FTP Server Disclosed

First seen 17 Jun 2026, 09:43 UTC Rapid7nvd.nist.govwww.ipswitch.comgithub.com 85% similarity 72.6

Article Content

Browse articles
ThreatCluster

On September 27, 2023, Progress Software disclosed CVE-2023-40044, a .NET deserialization vulnerability in the Ad Hoc Transfer module of WS_FTP Server. This flaw allows unauthenticated attackers to execute remote commands on affected systems. The vulnerability is present in versions prior to 8.7.4 and 8.8.2. Rapid7's analysis indicates that the vulnerability is trivially exploitable, with a suggested CVSS score of 9.8, contrasting with NIST's score of 8.8 due to differing interpretations of privilege requirements. The vulnerability was first publicly demonstrated with a proof of concept on October 2, 2023, and was added to CISA's Known Exploited Vulnerabilities Catalog on October 5, 2023. Organizations using affected versions are at significant risk, and immediate action is recommended to mitigate potential exploitation.

Key Points: • CVE-2023-40044 allows unauthenticated remote code execution in WS_FTP Server. • The vulnerability affects versions prior to 8.7.4 and 8.8.2 of the software. • Rapid7 suggests a CVSS score of 9.8, indicating high severity and exploitability.

ThreatCluster AI How this analysis works

Timeline

2023-09-27
CVE-2023-40044 published
Progress Software disclosed a .NET deserialization vulnerability in WS_FTP Server's Ad Hoc Transfer module.
Rapid7
2023-10-02
First public PoC released
A proof of concept demonstrating the exploitability of CVE-2023-40044 was made public.
Rapid7
2023-10-05
Added to CISA KEV
CVE-2023-40044 was included in CISA's Known Exploited Vulnerabilities Catalog due to active exploitation.
Rapid7

Community

Browse all →

Tracked Entities in This Story