ZeroHour
Security Affairspublished ()ingested @securityaffairs

+1,400 CrushFTP servers vulnerable to CVE-2024

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-4040

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4040
Unauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040)

CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers.

Do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited.

10.0100% KEV PoC ×2
  • CrushFTP All versions before 10.7.1 and 11.1.0, on all platforms
moderate≈1,400+ internet-exposed CrushFTP servers (public scan count), likely more including internal-only deployments
Full article266 words · extracted from securityaffairs.com · click to collapse

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability.

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks targeting the critical severity vulnerability CVE-2024-4040.

CVE-2024-4040 is a CrushFTP VFS sandbox escape vulnerability.

CrushFTP is a file transfer server software that enables secure and efficient file transfer capabilities. It supports various features such as FTP, SFTP, FTPS, HTTP, HTTPS, WebDAV, and WebDAV SSL protocols, allowing users to transfer files securely over different networks. CrushFTP also provides support for automation, scripting, user management, and extensive customization options meet the diverse needs of businesses and organizations.

In April, CrushFTP notified users of a virtual file system escape vulnerability impacting their FTP software, which could potentially enable users to download system files.

Simon Garrelou from the Airbus CERT discovered the vulnerability.

Crowdstrike researchers discovered that threat actors exploited the critical zero-day vulnerability in targeted attacks in the wild.

“On April 19, 2024, CrushFTP advised of a virtual file system escape present in their FTP software that could allows users to download system files. Falcon OverWatch and Falcon Intelligence have observed this exploit being used in the wild in a targeted fashion.” reads a post published by Crowdstrike on Reddit.

Security researchers from the Shadowserver reported that at least 1400 vulnerable servers were exposed online as of April 24, 2024. 

Most of the vulnerable servers are in the United States (725), followed by Germany (115), and Canada (108).

CISA this week added CVE-2024-4040 to its Known Exploited Vulnerabilities catalog.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/162319/hacking/crushftp-cve-2024-4040-vulnerable-servers.html