VYPR
Medium severity5.9NVD Advisory· Published Mar 19, 2025· Updated Jun 17, 2026

CVE-2025-2324

CVE-2025-2324

Description

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.

Affected products

3
  • from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2+ 2 more
    • (no CPE)range: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2
    • cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*range: >=2023.1.0,<2023.1.12
    • (no CPE)range: 2023.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.