• News/
  • https://www.bleepingcomputer.com/news/security/exploit-for-crushftp-rce-chain-released-patch-now/

Exploit for CrushFTP RCE chain released, patch now

BleepingComputer
·
Bill Toulas
·
Published Nov 18, 2023
·
Updated

A proof-of-concept exploit was publicly released for a critical remote code execution vulnerability in the CrushFTP enterprise suite, allowing unauthenticated attackers to access files on the server, execute code, and obtain plain-text passwords. The vulnerability was discovered in August 2023, tracked as CVE-2023-43177, by Converge security researchers, who responsibly reported it to the vendor. The developers released a fix overnight in version CrushFTP 10.5.2. Today, Converge published a proof-of-concept exploit for the CVE-2023-43177 flaw, making it critical for CrushFTP users to install the security updates as soon as possible. The CrushFTP exploit is conducted through an unauthenticated mass-assignment vulnerability, exploiting the AS2 header parsing to control user session properties. This allows attackers to read and delete files, potentially leading to complete system control and root-level remote code execution. The attackers can send payloads to the CrushFTP service on specific ports (80, 443, 8080, 9090) using web headers, which leave log traces. Next, the attackers overwrite session data using Java's 'putAll()' function, enabling the impersonation of 'administrators,' and leverage the 'drain_log()' function to manipulate files as needed to maintain stealthiness. Eventually, the attackers can leverage the 'sessions. obj' file in the program's installation folder to hijack live user sessions belonging to admin accounts, essentially achieving privileged escalation....

Read full article

Affected Software

1 affected component
CrushFTP CrushFTP enterprise suite=10.5.2

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in the CrushFTP enterprise suite, along with the release of a proof-of-concept exploit.

2

What security implications are discussed in the article?

The article highlights that unauthenticated attackers can exploit the vulnerability to access files, execute code, and retrieve plain-text passwords from the server.

3

What products or software are affected by this vulnerability?

The vulnerability affects the CrushFTP enterprise suite version 10.5.2.

4

What actions should users take following this news?

Users of CrushFTP are urged to apply the available patches immediately to mitigate the risks associated with the vulnerability.

5

Who is at risk from this remote code execution vulnerability?

Organizations using CrushFTP enterprise suite version 10.5.2 may be at risk if they do not update their software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203