← Back to browse · API

CVE-2023-40044

Severity
CRITICAL
CVSS
10.0
EPSS
0.9015
Risk score
56.55
CISA KEV
Yes
PoC
No
Published
2023-09-27
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-44651, GHSA-29VF-J74G-GMFC
Products
Progress Software Corporation:WS_FTP Server 8.7.0 <8.7.4, Progress Software Corporation:WS_FTP Server 8.8.0 <8.8.2, Progress:WS_FTP Server
Sources
cisa.gov CVE-2023-40044
euvd EUVD-2023-44651

Description

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

References