Progress Software fixed 2 critical severity flaws in WS_FTP Server
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-40044 | Unauthenticated Deserialization RCE in Progress WS_FTP Server CVE-2023-40044 is a .NET deserialization-of-untrusted-data flaw (CWE-502) in the Ad Hoc Transfer module of Progress WS_FTP Server. A remote attacker can trigger it by sending maliciously crafted input to that module before authentication, and successful exploitation yields arbitrary command execution on the underlying WS_FTP Server operating system. Any organization running WS_FTP Server versions prior to 8.7.4 or 8.8.2 is affected, with internet-facing file-transfer servers the most exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-05 with known ransomware use, public proof-of-concept exploits are available, and EPSS assigns a ~90% probability of exploitation within 30 days. Headlines indicate ransomware operators are actively targeting unpatched WS_FTP servers, making this a priority patch. Do: Upgrade WS_FTP Server to 8.7.4 or 8.8.2 (or later) per Progress's hotfix guidance; per CISA's KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. If patching cannot be done immediately, restrict or disable the Ad Hoc Transfer module and limit internet exposure of WS_FTP servers. Given confirmed ransomware use, prioritize internet-facing instances and review server and OS logs for signs of compromise or post-exploitation activity. | 8.8 | 90% | KEV ransomware PoC ×2 |
| large≈10,000+ internet-exposed WS_FTP servers (public scan data at disclosure time), with the total enterprise installed base likely several times larger |
Full article359 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 30, 2023

Progress Software has addressed a critical severity vulnerability in its WS_FTP Server software used by thousands of IT teams worldwide.
Progress Software warned customers to address a critical severity vulnerability, tracked as CVE-2023-40044 (CVSS score 10), in its WS_FTP Server software which is used by thousands of IT teams worldwide.
“The WS_FTP team recently discovered vulnerabilities in the WS_FTP Server Ad hoc Transfer Module and in the WS_FTP Server manager interface. All versions of WS_FTP Server are affected by these vulnerabilities.” reads the advisory from the vendor.
A pre-authenticated, remote attacker could leverage a .NET deserialization issue in the Ad Hoc Transfer module to execute arbitrary commands on the underlying WS_FTP Server operating system.
The issue affects WS_FTP Server versions prior to 8.7.4 and 8.8.2.
“In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.” reads the advisory.
In an advisory published on Wednesday, Progress disclosed multiple vulnerabilities impacting the software’s manager interface and Ad hoc Transfer Module.
Progress Software also addressed a directory traversal vulnerability tracked as CVE-2023-42657 (CVSS score 9.9). An attacker can trigger this flaw to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path.
“In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path.” reads the advisory. “Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system.”
Progress Software strongly recommends installing the security updates, the latest version addressing the flaws is 8.8.2.
The company also published instructions on how to remove or disable the vulnerable WS_FTP Server Ad Hoc Transfer Module.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, WS_FTP Server)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/151692/breaking-news/progress-software-ws_ftp-server-flaws.html