Skip to content
Detecteam
  • CompanyExpand
    • Founders Story
    • The Team
  • ProductExpand
    • About Us
  • SolutionsExpand
    • Use Cases
  • ResourcesExpand
    • Detecteam Blogs
    • Contact Us
Twitter Linkedin
Detecteam
Blog · Scenario

Critical Vulnerabilities in WS_FTP Server

Avatar photoByDetecteam 2023-10-252023-10-25

TLP

TLP CLEAR

Author

Sebastien Tricaud

Summary

Caitlin Condon, an expert at Rapid7, has highlighted critical vulnerabilities in WS_FTP Server, a secure file transfer solution. These vulnerabilities, notably CVE-2023-40044 and CVE-2023-42657, were disclosed by Progress Software on September 27, 2023. CVE-2023-40044, a .NET deserialization flaw, allows remote code execution with a single HTTPS POST request. Rapid7 has observed active exploitation of these vulnerabilities.

It’s crucial for WS_FTP Server users to update to version 8.8.2, as recommended by Progress Software, due to the severity of the vulnerabilities. Non-critical vulnerabilities like XSS and SQL injection issues were also identified. Rapid7 provides mitigation guidance and detection rules for its customers.

Rapid7 noticed a mass exploitation pattern, suggesting a single threat actor’s involvement, reinforcing the urgency of addressing these issues. The security community should take these vulnerabilities seriously to prevent further exploitation.

TIMELINE

DATA

We are providing data for attacks weekly hoping to contribute raising awareness to threats from their data.

windows_sysmon.xmlDownload

CATEGORY

0-day

references

  • https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/

MITRE ATT&CK

Post Tags: #T1005 - Data from Local Syste#T1048 - Exfiltration Over Alternative Protocol#T1059 - Command Line Interface#T1059.001 - Command and Scripting Interpreter: PowerShell#T1060 - Registry Run Keys / Startup Folder#T1064 - Scripting#T1073 - DLL Side-Loading#T1086 - Data Encrypted for Impact#T1209 - Exploitation of Vulnerability#T1562 - Defense Evasion
Avatar photo
Detecteam
X

Detecteam is transforming cybersecurity detection from static rule-writing to autonomous, continuous validation. Our REFLEX platform automates the detection lifecycle—building, testing, validating and deploying detections in minutes, not months. We help enterprises maximize ROI on existing tools, close high-risk detection gaps faster, and scale security outcomes without scaling headcount. This is the future of detection-as-code, and we’re leading it.

CONTACT US

Detecteam Inc.
300 Lenora Street PMB 659
Seattle, WA 98121 USA
+1 (650) 542-0831
sales@detecteam.com

  • Privacy Policy

SOCIAL MEDIA

Twitter Linkedin
OUR NEWSLETTER

Check your inbox or spam to confirm your subscription.

© 2025 Detecteam Inc. All Rights Reserved.

  • Company
    • Founders Story
    • The Team
  • Product
    • About Us
  • Solutions
    • Use Cases
  • Resources
    • Detecteam Blogs
    • Contact Us
Search