Rapid7
Critical RCE Vulnerability in WS_FTP Server Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On September 27, 2023, Progress Software disclosed CVE-2023-40044, a .NET deserialization vulnerability in the Ad Hoc Transfer module of WS_FTP Server. This flaw allows unauthenticated attackers to execute remote commands on affected systems. The vulnerability is present in versions prior to 8.7.4 and 8.8.2. Rapid7's analysis indicates that the vulnerability is trivially exploitable, with a suggested CVSS score of 9.8, contrasting with NIST's score of 8.8 due to differing interpretations of privilege requirements. The vulnerability was first publicly demonstrated with a proof of concept on October 2, 2023, and was added to CISA's Known Exploited Vulnerabilities Catalog on October 5, 2023. Organizations using affected versions are at significant risk, and immediate action is recommended to mitigate potential exploitation.
Key Points: • CVE-2023-40044 allows unauthenticated remote code execution in WS_FTP Server. • The vulnerability affects versions prior to 8.7.4 and 8.8.2 of the software. • Rapid7 suggests a CVSS score of 9.8, indicating high severity and exploitability.