CVE-2023-40044

Vulnerability updated 5 months ago (2024-05-04T17:37:58.251Z)
Download STIX
Preview STIX
CVE-2023-40044 is a critical vulnerability in the WS_FTP Server, a popular secure file transfer solution developed by Progress Software. This flaw, identified as a .NET deserialization vulnerability in the Ad Hoc Transfer Module, was disclosed alongside another vulnerability (CVE-2023-42657) and has received the highest possible CVSS rating of 10. The vulnerabilities were uncovered following a recent hack on Progress Software's MOVEit file-sharing tool. Rapid7 researchers reported "mass exploitation" of these recently disclosed flaws across multiple instances of WS_FTP Server software beginning on September 30, 2023. The critical nature of CVE-2023-40044, coupled with the availability of proof-of-concept (PoC) code, made it an attractive target for attackers, leading to widespread exploitation. In response to the discovery and subsequent exploitation of these vulnerabilities, Progress Software has released security updates to address both CVE-2023-40044 and CVE-2023-42657 in their WS_FTP Server software. Users of the software are strongly encouraged to apply these updates immediately to mitigate the risk posed by these critical vulnerabilities.
Description last updated: 2024-03-17T13:17:06.998Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Rapid7
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2023-40044 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
2 months ago
Securityaffairs
2 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago