CrushFTP zero-day exploited by attackers, upgrade immediately! (CVE-2024-4040)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4040 | Unauthenticated Sandbox Escape and RCE in CrushFTP (CVE-2024-4040) CrushFTP contains a server-side template injection flaw (CWE-94, CWE-1336) that allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. The flaw is triggered by unauthenticated network requests to any CrushFTP server running versions before 10.7.1 or 11.1.0 on any platform. Successful exploitation lets an attacker read files from the filesystem outside the VFS sandbox, bypass authentication to gain administrative access, and execute arbitrary code on the server. All CrushFTP deployments on prior versions are affected, especially internet-exposed file transfer servers. The vulnerability is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, EPSS puts 30-day exploitation probability at 99.5%, and public scans have identified at least 1,400 vulnerable exposed servers. Do: Upgrade immediately to CrushFTP 10.7.1 (10.x line) or 11.1.0 (11.x line) or later, as the vendor has urged, or apply the vendor's documented mitigations if patching is delayed. Prioritize internet-facing instances, and check them for signs of compromise such as unauthorized administrative access or unexpected file reads. Public proof-of-concept code exists, so assume unpatched exposed servers will be exploited. | 10.0 | 100% | KEV PoC ×2 |
| moderate≈1,400+ internet-exposed CrushFTP servers (public scan count), likely more including internal-only deployments |
Full article462 words · extracted from helpnetsecurity.com · click to collapse
A vulnerability (CVE-2024-4040) in enterprise file transfer solution CrushFTP is being exploited by attackers in a targeted fashion, according to Crowdstrike.

The vulnerability allows attackers to escape their virtual file system and download system files (i.e., configuration files), but only if the solution’s WebInterface is exposed on the internet.
According to Censys, there are currently 9,600+ publicly-exposed CrushFTP hosts (virtual & physical), mostly in North America and Europe.
About CVE-2024-4040
CrushFTP sent out notices about CVE-2024-4040 to customers on Friday (April 19).
“The bottom line of this vulnerability is that any unauthenticated or authenticated user via the WebInterface could retrieve system files that are not part of their VFS. This could lead to escalation as they learn more, etc.,” the company said.
Discovered by Simon Garrelou, a security engineer at Airbus CERT, the vulnerability affects CrushFTP v11 and v10, and has been patched in v11.1.0 and v10.7.1. Customers still running CrushFTP v9 should upgrade to version v11.1.0.
Customers using a DMZ in front of their main CrushFTP instance are only partially protected. All are advised to upgrade hosts immediately.
According to the company, there is no definitive way to check whether the exploit has been leveraged against an internet-facing CrushFTP host.
“The nature of this was common words that could be in your log already. So there is no silver bullet search term to check for,” they said.
The targets
These attacks against CrushFTP hosts seem to be reconnaissance efforts. Crowdstrike said that multiple US entities have been probed, and that this intelligence-gathering activity could be politically motivated.
But zero-days in enterprise-grade file transfer solutions have also lately been popular with ransomware-wielding attackers.
UPDATE (April 24, 2024, 04:45 a.m. ET):
Rapid7 has confirmed that the vulnerability is trivially exploitable, and that successful exploitation allows for: arbitrary file read as root, authentication bypass for administrator account access, full remote code execution, and access and potential exfiltration of all files stored on the CrushFTP instance.
Airbus CERT has published a script that triggers the vulnerability and a script that will look for indicators of compromise in a CrushFTP server installation directory.
“During the course of vulnerability analysis, Rapid7 observed several factors that make it difficult to effectively detect exploitation of CVE-2024-4040,” Rapid7’s Caitlin Condon noted.
“Payloads for CVE-2024-4040 can be delivered in many different forms. When certain evasive techniques are leveraged, payloads will be redacted from logs and request history, and malicious requests will be difficult to discern from legitimate traffic. CrushFTP instances behind a standard reverse proxy, such as NGINX or Apache, are partially defended against these techniques, but our team has found that evasive tactics are still possible.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/04/23/cve-2024-4040/