Skip to main content

CrushFTP Patches Exploited Zero-Day Vulnerability


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

CrushFTP patches a zero-day vulnerability allowing unauthenticated attackers to escape the VFS and retrieve system files.

 

April 22, 2024 By Ionut Arghire

 

CrushFTP on Friday released patches for a zero-day vulnerability in the file transfer server, warning customers of its in-the-wild exploitation.

Impacting CrushFTP versions 9, 10, and 11, the security defect allows an unauthenticated attacker to escape their virtual file system (VFS) and retrieve system files, potentially opening the door to further exploitation.

In its advisory, CrushFTP points out that customers using a DMZ server, which filters protocols and connections, are protected against attacks.

 

>> Full Article <<

0 replies

Be the first to reply!

Reply