CrushFTP urges customers to patch file transfer tool ‘ASAP’
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4040 | Unauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040) CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers. Do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited. | 10.0 | 100% | KEV PoC ×2 |
| moderate≈1,400+ internet-exposed CrushFTP servers (public scan count), likely more including internal-only deployments |
Full article392 words · extracted from therecord.media · click to collapse
A vulnerability in popular file transfer tool CrushFTP is already being exploited in attacks, the company said Monday. Last week, the company released both public and private notices to customers about a vulnerability affecting a version of their file transfer tool, which was first disclosed on April 19. The vulnerability was discovered by Airbus CERT’s Simon Garrelou and was given the tag CVE-2024-4040 on Monday afternoon. The latest version of the tool has a patch fixing the bug. A CrushFTP official told Recorded Future News that they do not yet know of any customers affected but that compromise is likely. “I am sure there have been, and they just are slow to apply updates and don't realize yet,” they said. “We have seen a customer who was already patched who was probed for the vulnerability. Had they not been updated, important config info would have been stolen. We can't stress enough that customers need to update ASAP, or block all IPs except known good IPs and operate in a whitelisting mode,” the official said. First reported by BleepingComputer, the vulnerability caused alarm because the company’s private notice said a user “could retrieve system files that are not part of their [virtual file system].” “This could lead to escalation as they learn more, etc,” the company told customers. Cybersecurity firm CrowdStrike released its own advisory saying their team has “observed this exploit being used in the wild in a targeted fashion.” CrowdStrike noted that “multiple U.S. entities were affected and said “intelligence-gather activity possibly politically motivated.” CrushFTP said it is difficult for customers to check if they have been exploited due to the type of the vulnerability, as there “is no silver bullet search term to check for” when searching through logs. File transfer tools are ripe targets for hackers interested in data theft. Two of the biggest security incidents in 2023 revolved around zero-day vulnerabilities in file transfer tools MOVEit and GoAnywhere — exposing thousands of organizations to hackers who stole troves of data on millions of people.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/crushftp-file-transfer-vulnerability-patch-asap