Critical severity10.0CISA KEVNVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-40044
CVE-2023-40044
Description
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:progress:ws_ftp_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:progress:ws_ftp_server:*:*:*:*:*:*:*:*range: <8.7.4
- (no CPE)range: 8.8.0
- Range: <8.7.4 and <8.8.2
Patches
Vulnerability mechanics
References
9- packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-Unauthenticated-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044nvdExploitThird Party Advisory
- attackerkb.com/topics/bn32f9sNax/cve-2023-40044nvdThird Party Advisory
- censys.com/cve-2023-40044/nvdThird Party Advisory
- community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023nvdVendor Advisory
- www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/nvdBroken LinkThird Party Advisory
- www.theregister.com/2023/10/02/ws_ftp_update/nvdPress/Media CoverageThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.progress.com/ws_ftpnvdProduct
News mentions
0No linked articles in our index yet.