Security News > 2023 > October > Exploit available for critical WS_FTP bug exploited in attacks

Exploit available for critical WS_FTP bug exploited in attacks
2023-10-02 17:11

Over the weekend, security researchers released a proof-of-concept exploit for a maximum severity remote code execution vulnerability in Progress Software's WS FTP Server file sharing platform.

"This vulnerability turned out to be relatively straight forward and represented a typical.NET deserialization issue that led to RCE. It's surprising that this bug has stayed alive for so long, with the vendor stating that most versions of WS FTP are vulnerable," Assetnote said.

"We have addressed the vulnerabilities above and the Progress WS FTP team strongly recommends performing an upgrade," Progress warned at the time.

Progress warns of maximum severity WS FTP Server vulnerability.

Exploit released for critical VMware SSH auth bypass vulnerability.

Exploit released for Ivanti Sentry bug abused as zero-day in attacks.


News URL

https://www.bleepingcomputer.com/news/security/exploit-available-for-critical-ws-ftp-bug-exploited-in-attacks/