KEVIntel
10.0
CVSS
Critical

CVE-2023-40044

PUBLISHED

WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Progress Software Corporation
Product
WS_FTP Server
Published
Sep 27, 2023
EPSS

Description

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

dotnet cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.1 10.0 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-10-05 00:00:00 UTC · Source

Used in malware

Recorded 2023-10-05 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Oct 05, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ws_ftp_rce_cve_2023_40044

metasploit · Created Unknown

Metasploit module for CVE-2023-40044

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit

  • Detected by Nuclei