CVE-2024-4040 exploited in the wild: everything you need to know
ID: 7b47de2b-5abc-5f10-8415-07e75f8f3081
STIX ID: report--7b47de2b-5abc-5f10-8415-07e75f8f3081
Feed Name: Wiz Blog
Threat Score
On April 19, 2024 CrushFTP disclosed CVE-2024-4040, a critical VFS sandbox escape affecting versions prior to 10.7.1 and 11.1.0; researchers escalated the severity after demonstrating unauthenticated remote code execution and observed exploitation in the wild. The flaw (CVSS 9.8) is exploitable via the web interface only, affects a subset of cloud deployments (Wiz reports ~1.7% vulnerable, ~0.4% internet-exposed), and organizations are advised to upgrade to 10.7.1 or 11.1.0 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
