logo

Critical Vulnerabilities: WS_FTP Exploitation

ID: 6afaa9c0-23f6-5944-9df5-d84c681f6460

STIX ID: report--6afaa9c0-23f6-5944-9df5-d84c681f6460

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Progress released an advisory for multiple WS_FTP Server Ad Hoc Transfer Module vulnerabilities; CVE-2023-40044 is a critical (CVSS 10) unauthenticated remote code execution flaw that researchers reproduced and that has been observed exploited in a small number of real-world cases. Huntress observed attacker behavior under the IIS worker process (w3wp.exe), including PowerShell and certutil commands used to fetch and run executables; the report lists IP addresses and TEMP executable paths as IOCs and urges patching to WS_FTP Server 2022.0.2 (8.8.2) or 2020.0.4 (8.7.4).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.