logo

CVE-2023-40044: WS_FTP exploit in the wild

ID: 1c35d968-4a89-537b-b072-917edd69f225

STIX ID: report--1c35d968-4a89-537b-b072-917edd69f225

Feed Name: ThreatLocker Blog

Threat Score
80/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

CVE-2023-40044 is a critical remote code execution vulnerability in the WS_FTP ad hoc module for IIS that can be triggered via a specially crafted POST request and is reported to be exploited in the wild; the advisory urges applying the WS_FTP patch and highlights ThreatLocker® Ringfencing™ as a mitigation to prevent post-exploitation process spawning and interaction with PowerShell/Command Line.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.