CVE-2024-4040
KEV PoC ×2moderateUnauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040)
CISA: CrushFTP VFS Sandbox Escape Vulnerability
CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers.
What to do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited.
| CrushFTP | All versions before 10.7.1 and 11.1.0, on all platforms |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
- Affected
- CrushFTP CrushFTP
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- crushftp
- Products
- crushftp
- Weakness
- CWE-1336, CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H