
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2023-40044 is a critical .NET deserialization vulnerability discovered in Progress Software's WSFTP Server's Ad Hoc Transfer module. The vulnerability, identified in September 2023, affects WSFTP Server versions prior to 8.7.4 and 8.8.2, allowing pre-authenticated attackers to execute remote commands on the underlying WS_FTP Server operating system (Assetnote Research, Progress Advisory).
The vulnerability exists in the MyFileUpload.UploadModule HTTP module, which handles file uploads within the Ad Hoc Transfer (AHT) application. The issue stems from unsafe deserialization of user input through the BinaryFormatter class, which can be triggered without authentication. The vulnerability received a CVSS base score of 8.8 from NIST and 10.0 from Progress Software, reflecting its critical severity (Assetnote Research, NVD).
The vulnerability affects approximately 2,900 internet-exposed WS_FTP Server instances, primarily belonging to large enterprises, governments, and educational institutions. Successful exploitation could lead to remote code execution on the underlying operating system, potentially compromising sensitive data and system integrity (Assetnote Research, Arctic Wolf).
Progress Software has released security patches for affected versions, recommending users upgrade to version 8.7.4 for WSFTP Server 2020 or version 8.8.2 for WSFTP Server 2022. As an alternative mitigation, users can disable or remove the Ad Hoc Transfer module if immediate patching is not feasible (Progress Advisory, Arctic Wolf).
The vulnerability has raised significant concerns in the cybersecurity community, particularly given Progress Software's recent history with the MOVEit Transfer exploitation. Security researchers expressed disappointment at how quickly proof-of-concept code was released after the patch, potentially giving threat actors a head start in exploitation attempts (The Register).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”