Article Details

Scrape Timestamp (UTC): 2023-09-29 06:21:40.598

Source: https://thehackernews.com/2023/09/progress-software-releases-urgent.html

Original Article Text

Click to Toggle View

Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP Server. Progress Software has released hotfixes for a critical security vulnerability, alongside seven other flaws, in the WS_FTP Server Ad hoc Transfer Module and in the WS_FTP Server manager interface. Tracked as CVE-2023-40044, the flaw has a CVSS score of 10.0, indicating maximum severity. All versions of the software are impacted by the flaw. "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system," the company said in an advisory. Assetnote security researchers Shubham Shah and Sean Yeoh have been credited with discovering and reporting the vulnerability. The list of remaining flaws, impacting WS_FTP Server versions prior to 8.8.2, is as follows - With security flaws in Progress Software becoming an attractive target for ransomware groups like Cl0p, it's essential that users move quickly to apply the latest patches to contain potential threats. Ready to tackle new AI-driven cybersecurity challenges? Join our insightful webinar with Zscaler to address the growing threat of generative AI in cybersecurity. The company, in the meanwhile, is still grappling with the fallout from the mass hack targeting its MOVEit Transfer secure file transfer platform since May 2023. More than 2,100 organizations and over 62 million individuals are estimated to have been impacted, according to Emsisoft.

Daily Brief Summary

CYBERCRIME // Progress Software Issues Hotfixes for Severe Flaws in WS_FTP Server

Progress Software released urgent hotfixes to correct a critical security flaw and seven other vulnerabilities in WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server manager interface.

The most severe flaw, tracked as CVE-2023-40044, has a CVSS score of 10.0, indicating maximum severity, and impacts all versions of the software.

This flaw allows a pre-authenticated hacker to execute remote commands on the underlying WS_FTP Server operating system through a .NET deserialization vulnerability in the Ad Hoc Transfer module.

Researchers Shubham Shah and Sean Yeoh from Assetnote discovered and reported this vulnerability.

Additional flaws affect versions of WS_FTP Server prior to 8.8.2, making them attractive targets for ransomware groups such as Cl0p, thus highlighting the importance of swift patch application.

Alongside issuing the hotfixes, Progress Software is also managing the fallout from a major hacking of its MOVEit Transfer secure file transfer platform since May 2023, which is estimated to have affected over 2,100 organizations and 62 million individuals.