iTnews Asia
  • Home
  • News
  • Security

Another Progress Software file transfer utility vulnerable

Another Progress Software file transfer utility vulnerable

WS_FTP has critical deserialisation bug.

By Richard Chirgwin on Oct 3, 2023 12:44PM

Progress Software, whose MOVEIt file transfer software was the vector for a variety of attacks earlier this year, has disclosed critical vulnerabilities in another package - and one is already being exploited.

CVE-2023-40044 was discovered by two researchers from Assetnote, Shubham Shah and Sean Yeoh.

On October 1, they wrote that Progress Software's WS_FTP package has a deserialisation vulnerability that affects "the entire Ad Hoc Transfer component" of the package.

In its advisory, Progress Software said: "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialisation vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system."

However, Shah and Yeoh claimed that "the vulnerability could be triggered without any authentication".

Assetnote said its scans revealed nearly 3000 hosts on the internet that matched the conditions for exploitation - they are running WS_FTP and they have an accessible web server, and most "belong to large enterprises, governments and educational institutions".

Progress Software disclosed a number of other vulnerabilities in its advisory, including CVE-2023-42657, a critical-rated directory traversal bug that allows attackers to perform file operations (including deleting and renaming files and directories) on locations on the underlying operating system.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
progress software security software

Related Articles

  • Fulbright University Vietnam adopts AI assistant to cut service delays
  • Many Singapore and APAC enterprises held back by poor software quality
  • How making identity a priority can help bring clarity to AI chaos
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

Five tips a CIO or CSO should know to stop employee-driven IP theft

Five tips a CIO or CSO should know to stop employee-driven IP theft

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

Philippine education ministry hit by data leak exposing 210,020 records

Philippine education ministry hit by data leak exposing 210,020 records

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.