ZeroHour

CVE-2024-23692

KEV ransomware PoC ×5large1

Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3m

CISA: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

Rejetto HTTP File Server (HFS), a free Windows-based file-sharing server, contains a template injection vulnerability (CWE-94/CWE-1336) in versions up to and including 2.3m that allows a remote, unauthenticated attacker to execute arbitrary commands by sending a specially crafted HTTP request. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.8 Critical), and the affected 2.3m release is no longer supported by the vendor. Any system running Rejetto HFS 2.3m or earlier is affected, with instances exposed directly to the internet at the greatest risk. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-07-09 with known ransomware use, EPSS assigns a 99.5% probability of exploitation within 30 days, and public PoCs and a Metasploit module are available. Related reporting on Russia-aligned TAG-110 activity (HATVIBE/CHERRYSPY malware) against Ukrainian institutions highlights active targeting around the same period.

What to do: Because HFS 2.3m is end-of-life with no fixed 2.x version indicated in the available data, follow CISA's required action: apply mitigations per vendor instructions or discontinue use of the product, and at minimum remove it from direct internet exposure (firewall/ACL rules or VPN-only access). Hunt for compromise by checking HFS access logs for crafted HTTP requests containing template/macro syntax and the HFS service process for unexpected child processes. Organizations subject to CISA KEV remediation deadlines should prioritize this fix given the 9.8 Critical severity, 99.5% EPSS, and known ransomware use.

Affected
rejetto HTTP File Serverup to and including 2.3m (end-of-life, no longer supported)
Estimated exposure
largetens of thousands of internet-exposed HFS 2.3m instances (order of magnitude 10k–100k systems) — Public internet scan data (e.g., Shodan) has long shown tens of thousands of exposed Rejetto HFS 2.3 servers, a footprint consistent with the product's popularity as a quick Windows file-sharing tool; this is an estimate, not an exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

CISA Known Exploited Vulnerability
Affected
Rejetto HTTP File Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
rejetto
Products
http file server
Weakness
CWE-1336, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news