• News/
  • https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/

CrushFTP warns users to patch exploited zero-day “immediately”

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 19, 2024
·
Updated

Update April 22, 16:31 EDT: This CrushFTP VFS sandbox escape vulnerability is now tracked as CVE-2024-4040. CrushFTP warned customers today in a private memo of an actively exploited zero-day vulnerability fixed in new versions released today, urging them to patch their servers immediately. As the company also explains in a public security advisory published on Friday, this zero-day bug enables unauthenticated attackers to escape the user's virtual file system (VFS) and download system files. However, those using a DMZ (demilitarized zone) perimeter network in front of their main CrushFTP instance are protected against attacks. "Please take immediate action to patch ASAP. A vulnerability was reported today (April 19th, 2024), and we patched it immediately. [..] This vulnerability exists in the wild," the company warned customers via email. "The bottom line of this vulnerability is that any unauthenticated or authenticated user via the WebInterface could retrieve system files that are not part of their VFS. This could lead to escalation as they learn more, etc." The company also warned customers with servers still running CrushFTP v9 to immediately upgrade to v11 or update their instance via the dashboard. "There is a simple rollback in case you have an issue or regression with some functionality. Update immediately," CrushFTP warned. The security flaw was reported by Simon Garrelou of Airbus CERT and is now fixed in CrushFTP versions 10.7.1 and 11.1.0. According to Shodan, a...

Read full article

Affected Software

1 affected component
CrushFTP CrushFTP<10.7.1, <11.1.0

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability in CrushFTP that users are urged to patch immediately.

2

What specific vulnerability is identified in CrushFTP?

The vulnerability is a VFS sandbox escape, tracked as CVE-2024-4040.

3

Who should be concerned about this security issue?

All users of CrushFTP versions 10.7.1 and above should be concerned and take immediate action.

4

What actions should CrushFTP users take in response to the zero-day exploit?

Users are advised to update to the latest versions of CrushFTP to mitigate the security risk.

5

What versions of CrushFTP are affected by the zero-day vulnerability?

CrushFTP versions 10.7.1 and 11.1.0 and above are affected by the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203