MOVEit maker announces new critical vulnerability affecting a different file transfer tool
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-40044 | Unauthenticated Deserialization RCE in Progress WS_FTP Server CVE-2023-40044 is a .NET deserialization-of-untrusted-data flaw (CWE-502) in the Ad Hoc Transfer module of Progress WS_FTP Server. A remote attacker can trigger it by sending maliciously crafted input to that module before authentication, and successful exploitation yields arbitrary command execution on the underlying WS_FTP Server operating system. Any organization running WS_FTP Server versions prior to 8.7.4 or 8.8.2 is affected, with internet-facing file-transfer servers the most exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-05 with known ransomware use, public proof-of-concept exploits are available, and EPSS assigns a ~90% probability of exploitation within 30 days. Headlines indicate ransomware operators are actively targeting unpatched WS_FTP servers, making this a priority patch. Do: Upgrade WS_FTP Server to 8.7.4 or 8.8.2 (or later) per Progress's hotfix guidance; per CISA's KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. If patching cannot be done immediately, restrict or disable the Ad Hoc Transfer module and limit internet exposure of WS_FTP servers. Given confirmed ransomware use, prioritize internet-facing instances and review server and OS logs for signs of compromise or post-exploitation activity. | 8.8 | 90% | KEV ransomware PoC ×2 |
| large≈10,000+ internet-exposed WS_FTP servers (public scan data at disclosure time), with the total enterprise installed base likely several times larger | |
| CVE-2023-42657 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system. NVD description · AI analysis pending | 9.6 | 17% |
| — |
Full article718 words · extracted from therecord.media · click to collapse
The company behind a popular file transfer service that was exploited by ransomware hackers has announced a new set of vulnerabilities affecting another file transfer tool. Progress Software — the company behind the widely exploited MOVEit file transfer tool — said this week that one of their other products, WS_FTP Server, has several vulnerabilities that need to be patched immediately. Thousands of IT teams depend on WS_FTP Server for “the unique business-grade features required to assure reliable and secure transfer of critical data,” according to the company. Progress listed the Denver Broncos, gaming company RockSteady, H&M Software and Scientific American as some customers using the WS_FTP product. On Wednesday, Progress published an advisory warning that their team and outside researchers discovered eight new vulnerabilities. All versions of WS_FTP Server are affected by these vulnerabilities, and the company made version-specific hotfixes available for customers to remediate them. “We have responsibly disclosed this vulnerability in conjunction with the researchers at Assetnote," Progress said in a statement to Recorded Future News. "Currently, we have not seen any indication that this vulnerability has been exploited. We have issued a fix and have encouraged our customers to perform an upgrade to the patched version of our software. Security is of the utmost importance to us and we leverage development practices to minimize product vulnerabilities whenever possible.” The most serious of the issues – CVE-2023-40044 and CVE-2023-42657 – carry CVSS severity scores of 10 and 9.9 respectively, indicating that they are critical issues that companies should quickly address. CVE-2023-40044 was discovered by two security experts from AssetNote, CTO Shubham Shah and engineering lead Sean Yeoh, and would allow a hacker to execute commands on a victim system. CVE-2023-42657 was discovered by Progress Software and could be used by attackers to delete or rename files on a variety of victim assets. Several other issues were discovered by Deloitte’s Cristian Mocanu and carry severity scores ranging from 5.3 to 8.3. “Upgrading to a patched release, using the full installer, is the only way to remediate this issue. There will be an outage to the system while the upgrade is running,” the company said. Progress Software is now facing several class action lawsuits and severe backlash over the exploitation of vulnerabilities affecting MOVEit – a popular file transfer software used by hundreds of governments, corporations and universities. The Clop ransomware gang spent weeks stealing sensitive information through the file transfer software, setting off a global patching effort that was considered successful but did little to stop the gang from extracting troves of data. Security firm Emsisoft estimates that more than 62 million people and 2,000 organizations were affected by the MOVEit breaches. Cybersecurity researchers believe the Clop gang has ended up netting anywhere from $75 million to $100 million just from the MOVEit campaign — with that sum “coming from just a small handful of victims that succumbed to very high ransom payments.” Progress recently told investors that the incident would have a “minimal” business impact on the company, Cybersecurity Dive reported Thursday. File transfer tools have long been a target of hackers due to the access they provide to sensitive data. The Clop ransomware gang previously exploited Fortra’s GoAnywhere file transfer product earlier this year and Accellion’s file transfer appliance in 2021. Dustin Childs – head of threat awareness at Trend Micro’s Zero Day Initiative – told Recorded Future News this summer that defenders should be on the lookout for file transfer software attacks because they are in the “very soft middle” of organizations’ networks. “Attackers – especially the ransomware crews – are gonna start looking at those [file transfer zero days] because people are getting a little smarter with not clicking on stuff and not responding to the scam emails,” he said. “And by the way, MOVEit is not the only product in that field. There are other file transfer appliances out there. How secure are they? I would imagine if you've got a file transfer appliance, it's probably a target.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/progress-new-file-transfer-vulnerability