iTnews Asia
  • Home
  • News
  • Security

Another Progress Software file transfer utility vulnerable

Another Progress Software file transfer utility vulnerable

WS_FTP has critical deserialisation bug.

By Richard Chirgwin on Oct 3, 2023 12:44PM

Progress Software, whose MOVEIt file transfer software was the vector for a variety of attacks earlier this year, has disclosed critical vulnerabilities in another package - and one is already being exploited.

CVE-2023-40044 was discovered by two researchers from Assetnote, Shubham Shah and Sean Yeoh.

On October 1, they wrote that Progress Software's WS_FTP package has a deserialisation vulnerability that affects "the entire Ad Hoc Transfer component" of the package.

In its advisory, Progress Software said: "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialisation vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system."

However, Shah and Yeoh claimed that "the vulnerability could be triggered without any authentication".

Assetnote said its scans revealed nearly 3000 hosts on the internet that matched the conditions for exploitation - they are running WS_FTP and they have an accessible web server, and most "belong to large enterprises, governments and educational institutions".

Progress Software disclosed a number of other vulnerabilities in its advisory, including CVE-2023-42657, a critical-rated directory traversal bug that allows attackers to perform file operations (including deleting and renaming files and directories) on locations on the underlying operating system.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
progress software security software

Related Articles

  • The maritime sector is now in the crosshairs of cybercriminals
  • Thai Airways launches digital loyalty transformation
  • Tips on how to harness AI to transform your DDoS protection into proactive cyber defence
  • Malaysia secures communications for the upcoming ASEAN Summit
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The maritime sector is now in the crosshairs of cybercriminals

The maritime sector is now in the crosshairs of cybercriminals

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Malaysia secures communications for the upcoming ASEAN Summit

Malaysia secures communications for the upcoming ASEAN Summit

IMDA and Enterprise Singapore launch SME-focused cybersecurity initiative

IMDA and Enterprise Singapore launch SME-focused cybersecurity initiative

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.