Back to overview

CVE-2023-40044

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

Metadata

CVE ID
CVE-2023-40044
State
PUBLISHED
Assigner
ProgressSoftware
Reserved
2023-08-08 19:44 UTC
Published
2023-09-27 14:48 UTC
Last updated
2025-10-21 23:05 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
Progress Software Corporation / WS_FTP Server
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Vendor
Progress
Product
WS_FTP Server
Added to KEV
2023-10-05
Due date
2023-10-26
Ransomware
Known use
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA description
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Affected products (1)
VendorProductPlatformVersions
Progress Software Corporation WS_FTP Server 8.8.0 < 8.8.2, 8.7.0 < 8.7.4
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview