VYPR
Unrated severityCISA KEVNVD Advisory· Published Sep 27, 2023· Updated Oct 21, 2025

WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability

CVE-2023-40044

Description

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

Affected products

1
  • Progress Software Corporation/WS_FTP Serverv5
    Range: 8.8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.