CVE-2023-36933: High severity Progress MOVEit Transfer vulnerability
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-36933?
CVE-2023-36933 is a vulnerability in Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4) that allows an attacker to invoke a method resulting in an unhandled exception.
How severe is CVE-2023-36933?
CVE-2023-36933 has a severity rating of 7.5 (high).
What software versions are affected by CVE-2023-36933?
Progress MOVEit Transfer versions before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4) are affected by CVE-2023-36933.
How can an attacker exploit CVE-2023-36933?
An attacker can exploit CVE-2023-36933 by invoking a method that causes an unhandled exception in the MOVEit Transfer application.
Are there any references for CVE-2023-36933?
Yes, you can find more information about CVE-2023-36933 at the following references: [1](https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023) [2](https://www.progress.com/moveit)