CVE-2023-40044: WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
In WSFTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WSFTP Server operating system.
Other sources
Progress WSFTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress WS_FTP Serverto a version that resolves this vulnerability.Fixed in 8.7.4 - Upgrade
Upgrade
Progress WS_FTP Serverto a version that resolves this vulnerability.Fixed in 8.8.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40044?
The severity of CVE-2023-40044 is critical with a severity score of 8.8.
What is the affected software for CVE-2023-40044?
The affected software for CVE-2023-40044 is WS_FTP Server versions prior to 8.7.4 and 8.8.2.
How can a pre-authenticated attacker exploit this vulnerability?
A pre-authenticated attacker can exploit this vulnerability by leveraging a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
Are there any suggested solutions or fixes for CVE-2023-40044?
To fix CVE-2023-40044, you should update your WS_FTP Server to version 8.7.4 or higher, or version 8.8.2 or higher.
Can you provide more information about CVE-2023-40044?
For more information about CVE-2023-40044, you can refer to the following references: [Link 1](https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023), [Link 2](https://www.progress.com/ws_ftp).