CVE-2023-6218: MOVEit Transfer Group Admin Privilege Escalation
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-6218?
CVE-2023-6218 is a vulnerability in MOVEit Transfer that allows a group administrator to escalate a group member's permissions.
How severe is CVE-2023-6218?
CVE-2023-6218 has a severity rating of 7.2, which is considered high.
Which versions of MOVEit Transfer are affected by CVE-2023-6218?
MOVEit Transfer versions released before 2022.0.9, 2022.1.10, and 2023.0.7 are affected by CVE-2023-6218.
How can I fix CVE-2023-6218?
To fix CVE-2023-6218, you should update MOVEit Transfer to version 2022.0.9, 2022.1.10, or 2023.0.7 or higher.
Where can I find more information about CVE-2023-6218?
You can find more information about CVE-2023-6218 on the Progress MOVEit website and the Progress Community.