ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

MOVEit Developer Patches Critical File Transfer Bug

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-40044
Unauthenticated Deserialization RCE in Progress WS_FTP Server

CVE-2023-40044 is a .NET deserialization-of-untrusted-data flaw (CWE-502) in the Ad Hoc Transfer module of Progress WS_FTP Server. A remote attacker can trigger it by sending maliciously crafted input to that module before authentication, and successful exploitation yields arbitrary command execution on the underlying WS_FTP Server operating system. Any organization running WS_FTP Server versions prior to 8.7.4 or 8.8.2 is affected, with internet-facing file-transfer servers the most exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-05 with known ransomware use, public proof-of-concept exploits are available, and EPSS assigns a ~90% probability of exploitation within 30 days. Headlines indicate ransomware operators are actively targeting unpatched WS_FTP servers, making this a priority patch.

Do: Upgrade WS_FTP Server to 8.7.4 or 8.8.2 (or later) per Progress's hotfix guidance; per CISA's KEV required action, apply vendor mitigations or discontinue use if patching is unavailable. If patching cannot be done immediately, restrict or disable the Ad Hoc Transfer module and limit internet exposure of WS_FTP servers. Given confirmed ransomware use, prioritize internet-facing instances and review server and OS logs for signs of compromise or post-exploitation activity.

8.890% KEV ransomware PoC ×2
  • Progress WS_FTP Server All versions prior to 8.7.4 and prior to 8.8.2 (the Ad Hoc Transfer module is the vulnerable component)
large≈10,000+ internet-exposed WS_FTP servers (public scan data at disclosure time), with the total enterprise installed base likely several times larger
CVE-2023-42657
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path. Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system.

NVD description · AI analysis pending
9.617%
  • progress ws ftp server
Full article405 words · extracted from infosecurity-magazine.com · click to collapse

Progress Software has urged customers to patch a critical new vulnerability in one of its flagship file transfer software products, which could impact thousands of customers worldwide.

The software company is more famous for MOVEit, a managed file transfer offering which was recently exploited to devastating effect by the Clop ransomware gang.

However, the CVSS 10.0 vulnerability, CVE-2023-40044, is found in the firm’s WS_FTP product.

“In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system,” the advisory noted. “All versions of WS_FTP Server Ad hoc module are affected by this vulnerability.”

In fact, there are eight vulnerabilities in all addressed by the firm’s updates, impacting the WS_FTP Server Ad Hoc Transfer Module and the WS_FTP Server manager interface, two of which are critical.

The other critical bug, CVE-2023-42657, has a CVSS score of 9.9 and is a directory traversal vulnerability affecting WS_FTP Server versions prior to 8.7.4 and 8.8.2.

Read more on MOVEit: Clop Ransom Gang Breaches Big Names Via MOVEit Flaw

“An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder path,” the advisory explained.

“Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system.”

Callie Guenther, senior manager for cyber threat research at Critical Start, argued that the vulnerabilities required immediate attention.

“The WS_FTP Team has responded by issuing clear and detailed communication, outlining the affected versions, providing links to hotfixes, recommending an upgrade to the latest version (8.8.2), and suggesting mitigation steps for immediate action,” she added.

“However, organizations should note that remediation requires a system outage during the upgrade, necessitating effective communication and planning to minimize operational impact.”

A statement from Progress Software sent to Infosecurity had the following:

“We have responsibly disclosed these vulnerabilities in conjunction with the researchers at Assetnote. Currently, we have not seen any indication that these vulnerabilities have been exploited. We have issued a fix and have encouraged our customers to perform an upgrade to the patched version of our software. Security is of the utmost importance to us and we leverage development practices to minimize product vulnerabilities whenever possible.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/moveit-patches-critical-file/