CVE-2024-23692
KEV ransomware PoC ×5large1Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3m
CISA: Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Rejetto HTTP File Server (HFS), a free Windows-based file-sharing server, contains a template injection vulnerability (CWE-94/CWE-1336) in versions up to and including 2.3m that allows a remote, unauthenticated attacker to execute arbitrary commands by sending a specially crafted HTTP request. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.8 Critical), and the affected 2.3m release is no longer supported by the vendor. Any system running Rejetto HFS 2.3m or earlier is affected, with instances exposed directly to the internet at the greatest risk. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-07-09 with known ransomware use, EPSS assigns a 99.5% probability of exploitation within 30 days, and public PoCs and a Metasploit module are available. Related reporting on Russia-aligned TAG-110 activity (HATVIBE/CHERRYSPY malware) against Ukrainian institutions highlights active targeting around the same period.
What to do: Because HFS 2.3m is end-of-life with no fixed 2.x version indicated in the available data, follow CISA's required action: apply mitigations per vendor instructions or discontinue use of the product, and at minimum remove it from direct internet exposure (firewall/ACL rules or VPN-only access). Hunt for compromise by checking HFS access logs for crafted HTTP requests containing template/macro syntax and the HFS service process for unexpected child processes. Organizations subject to CISA KEV remediation deadlines should prioritize this fix given the 9.8 Critical severity, 99.5% EPSS, and known ransomware use.
| rejetto HTTP File Server | up to and including 2.3m (end-of-life, no longer supported) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
- Affected
- Rejetto HTTP File Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- rejetto
- Products
- http file server
- Weakness
- CWE-1336, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H