Hackers Are Exploiting Critical Vulnerabilities in File Transfer Software

Hackers Are Exploiting Critical Vulnerabilities in File Transfer Software

Source: YouTube · John Hammond · published Oct 3, 2023 · 21:31

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Progress Software released a security advisory for a critical CVSS 10.0 vulnerability (CVE-2023-40044) in WS_FTP Server that allows pre-authentication remote code execution via a deserialization flaw 0:24-0:50.

Key Takeaways:
• CVE-2023-40044 is the most critical of several vulnerabilities disclosed, and users are urged to patch immediately as exploits are currently observed in the wild 0:24-0:41 2:23-2:31.
• Discovered by Assetnote, the vulnerability is triggered by a single HTTP POST request containing a Base64 encoded .NET deserialization payload targeting the Ad Hoc Transfer module 1:09-1:52.
• Post-exploitation activity involves living-off-the-land techniques like certutil to download payloads and PowerShell scripts designed to bypass AMSI and disable logging 3:40-3:57.

While responsible disclosure prevented a mass ransomware event similar to MOVEit, the public release of proof-of-concept code has led to active exploitation targeting unpatched systems 1:57-2:22.

Sources:

  • 0:24-0:50 Discussion of CVE-2023-40044 criticality and impact
  • 1:09-1:52 Discovery details and exploit mechanics via HTTP POST
  • 2:23-2:31 In-the-wild exploitation observations
  • 3:40-3:57 Post-exploitation activity analysis

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

progress the very same company that was in the center of the storm during the move it transfer exploitation has just recently released another security advisory disclosing a handful of different new vulnerabilities and cves this knowledge-based article was released on September 27th and it's discussing the new vulnerabilities present in the wsftp server ad hoc transfer module and the wsftp server manager interface now Chief among these vulnerabilities is cve 20234 0044 with a CVSs score of 10 the highest you can get absolutely critical vulnerability and that includes in these versions these are all patched by the way if you haven't yet hey please go update to the latest rendition but there is a pre-authentication technique to leverage a derealization vulnerability that offers a threat acto…