iTnews Asia
  • Home
  • News
  • Security

Another Progress Software file transfer utility vulnerable

Another Progress Software file transfer utility vulnerable

WS_FTP has critical deserialisation bug.

By Richard Chirgwin on Oct 3, 2023 12:44PM

Progress Software, whose MOVEIt file transfer software was the vector for a variety of attacks earlier this year, has disclosed critical vulnerabilities in another package - and one is already being exploited.

CVE-2023-40044 was discovered by two researchers from Assetnote, Shubham Shah and Sean Yeoh.

On October 1, they wrote that Progress Software's WS_FTP package has a deserialisation vulnerability that affects "the entire Ad Hoc Transfer component" of the package.

In its advisory, Progress Software said: "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialisation vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system."

However, Shah and Yeoh claimed that "the vulnerability could be triggered without any authentication".

Assetnote said its scans revealed nearly 3000 hosts on the internet that matched the conditions for exploitation - they are running WS_FTP and they have an accessible web server, and most "belong to large enterprises, governments and educational institutions".

Progress Software disclosed a number of other vulnerabilities in its advisory, including CVE-2023-42657, a critical-rated directory traversal bug that allows attackers to perform file operations (including deleting and renaming files and directories) on locations on the underlying operating system.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
progress software security software

Related Articles

  • Sophos: Identity attacks have overtaken software flaws as entry point of ransomware
  • Strategies to mitigate against the real world impact of identity attacks
  • How can the Agentic AI workspace remain secure for APAC organisations?
  • AI-fuelled attacks forcing enterprises to rethink security architecture
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Philippines Maxicare, Jollibee Foods Corporation hit by data breach

Singtel appoints new group CISO

Singtel appoints new group CISO

How severe will ransomware attacks become in 2026?

How severe will ransomware attacks become in 2026?

EU drops sovereignty requirements in cybersecurity certification scheme

EU drops sovereignty requirements in cybersecurity certification scheme

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.