ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Ransomware Targets Unpatched WS_FTP Servers

criticalRansomwareimportance 60CVE-2023-40044

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-40044
Unauthenticated Deserialization RCE in Progress WS_FTP Server

CVE-2023-40044 is a .NET deserialization-of-untrusted-data flaw (CWE-502) in the Ad Hoc Transfer module of Progress WS_FTP Server. A remote attacker can trigger it by sending maliciously crafted input to that module before authentication, and successful exploitation yields arbitrary command execution on the underlying WS_FTP Server operating system. Any organization running WS_FTP Server versions prior to 8.7.4 or 8.8.2 is affected, with internet-facing file-transfer servers the most exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-05 with known ransomware use, public proof-of-concept exploits are available, and EPSS assigns a ~90% probability of exploitation within 30 days. Headlines indicate ransomware operators are actively targeting unpatched WS_FTP servers, making this a priority patch.

Do: Upgrade WS_FTP Server to 8.7.4 or 8.8.2 (or later) per Progress's hotfix guidance; per CISA's KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. If patching cannot be done immediately, restrict or disable the Ad Hoc Transfer module and limit internet exposure of WS_FTP servers. Given confirmed ransomware use, prioritize internet-facing instances and review server and OS logs for signs of compromise or post-exploitation activity.

8.890% KEV ransomware PoC ×2
  • Progress WS_FTP Server All versions prior to 8.7.4 and prior to 8.8.2 (the Ad Hoc Transfer module is the vulnerable component)
large≈10,000+ internet-exposed WS_FTP servers (public scan data at disclosure time), with the total enterprise installed base likely several times larger
Full article381 words · extracted from infosecurity-magazine.com · click to collapse

Unpatched WS_FTP servers exposed to the internet have become prime targets for ransomware attacks, with threat actors exploiting a critical vulnerability. 

Writing on Infosec Exchange last Thursday, Sophos X-Ops’ incident responders described an attempted ransomware attack by the self-proclaimed Reichsadler Cybercrime Group. The attack reportedly utilized a stolen LockBit 3.0 builder to create ransomware payloads.

Despite Progress Software releasing a patch for the WS_FTP Server vulnerability (tracked CVE-2023-40044) just last month, not all servers have been updated, leaving them vulnerable to exploitation. 

In this particular attack, the threat actors attempted to escalate privileges using the open-source GodPotato tool, known for enabling privilege escalation across various Windows client and server platforms.

Sophos X-Ops revealed the attack sequence on Mastodon. The attack began with exploitation of the critical vulnerability, eventually leading to the attempted ransomware deployment. Fortunately, Sophos X-Ops managed to thwart the attack with their behavioral protection rules and multi-layered security measures.

“It appears that the attackers have only really been able to deploy ransomware on the victims’ machine that is running this FTP software itself. However, industry sectors that use the software for transferring files remain vulnerable,” warned John Bambenek, principal threat hunter at Netenrich.

“Of particular concern is the medical sector, where not only file transfers from going between providers are important, the lack of being able to access those records on a timely basis could certainly impact patient care and potentially mortality rates.”

According to Melissa Bischoping, director of endpoint security research at Tanium, this incident is a stark reminder of the critical importance of promptly patching known vulnerabilities and maintaining up-to-date security defenses.

“Any vulnerability in a public-facing device like web servers, FTP servers, or network infrastructure is an attractive target for a threat actor to compromise. Some organizations may face delayed patching either due to visibility challenges or delays to avoid disruptive downtime,” Bischoping explained.

Read more about CVE-2023-40044: MOVEit Developer Patches Critical File Transfer Bugs

“As part of your security strategy, having a plan of action to mitigate and patch vulnerabilities in those critical and exposed services should be part of your vulnerability management planning,” Bischoping added.

To enhance defenses and gain insight into this latest threat, organizations can refer to the indicators of compromise (IOCs) made available on Sophos X-Ops’ GitHub page.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ransomware-targets-unpatched-wsftp/