ZeroHour

CVE-2024-4040

KEV PoC ×2moderate

Unauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040)

CISA: CrushFTP VFS Sandbox Escape Vulnerability

CVSS 3.1
10.0 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers.

What to do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited.

Affected
CrushFTPAll versions before 10.7.1 and 11.1.0, on all platforms
Estimated exposure
moderate≈1,400+ internet-exposed CrushFTP servers (public scan count), likely more including internal-only deployments — News coverage citing public internet scans reported roughly 1,400 vulnerable CrushFTP servers exposed, a likely undercount because CrushFTP is often deployed internally for enterprise file transfer.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CISA Known Exploited Vulnerability
Affected
CrushFTP CrushFTP
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
crushftp
Products
crushftp
Weakness
CWE-1336, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news