
Hackers Are Exploiting Critical Vulnerabilities in File Transfer Software
Source: YouTube · John Hammond · published Oct 3, 2023 · 21:31
Progress Software released a security advisory for a critical CVSS 10.0 vulnerability (CVE-2023-40044) in WS_FTP Server that allows pre-authentication remote code execution via a deserialization flaw 0:24-0:50.
Key Takeaways:
• CVE-2023-40044 is the most critical of several vulnerabilities disclosed, and users are urged to patch immediately as exploits are currently observed in the wild 0:24-0:41 2:23-2:31.
• Discovered by Assetnote, the vulnerability is triggered by a single HTTP POST request containing a Base64 encoded .NET deserialization payload targeting the Ad Hoc Transfer module 1:09-1:52.
• Post-exploitation activity involves living-off-the-land techniques like certutil to download payloads and PowerShell scripts designed to bypass AMSI and disable logging 3:40-3:57.
While responsible disclosure prevented a mass ransomware event similar to MOVEit, the public release of proof-of-concept code has led to active exploitation targeting unpatched systems 1:57-2:22.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
progress the very same company that was in the center of the storm during the move it transfer exploitation has just recently released another security advisory disclosing a handful of different new vulnerabilities and cves this knowledge-based article was released on September 27th and it's discussing the new vulnerabilities present in the wsftp server ad hoc transfer module and the wsftp server manager interface now Chief among these vulnerabilities is cve 20234 0044 with a CVSs score of 10 the highest you can get absolutely critical vulnerability and that includes in these versions these are all patched by the way if you haven't yet hey please go update to the latest rendition but there is a pre-authentication technique to leverage a derealization vulnerability that offers a threat acto…