Critical Vulnerabilities: WS_FTP Exploitation
ID: 6afaa9c0-23f6-5944-9df5-d84c681f6460
STIX ID: report--6afaa9c0-23f6-5944-9df5-d84c681f6460
Feed Name: Huntress Blog
Progress released an advisory for multiple WS_FTP Server Ad Hoc Transfer Module vulnerabilities; CVE-2023-40044 is a critical (CVSS 10) unauthenticated remote code execution flaw that researchers reproduced and that has been observed exploited in a small number of real-world cases. Huntress observed attacker behavior under the IIS worker process (w3wp.exe), including PowerShell and certutil commands used to fetch and run executables; the report lists IP addresses and TEMP executable paths as IOCs and urges patching to WS_FTP Server 2022.0.2 (8.8.2) or 2020.0.4 (8.7.4).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
