Medium severity5.9NVD Advisory· Published Mar 19, 2025· Updated Jun 17, 2026
CVE-2025-2324
CVE-2025-2324
Description
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.
Affected products
3from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2+ 2 more
- (no CPE)range: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2
- cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*range: >=2023.1.0,<2023.1.12
- (no CPE)range: 2023.1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.