Progress WS_FTP Server's Ad Hoc Transfer (AHT) component is vulnerable to unauthenticated remote code execution tracked as CVE-2023-40044. An attacker with network access to the WS_FTP web server can submit a crafted multipart HTTP request that delivers attacker-controlled Base64 data to a .NET BinaryFormatter deserialization sink in the MyFileUpload.UploadModule IIS HTTP module, allowing arbitrary command execution without credentials.
The issue affects WS_FTP Server releases before 8.7.4 and 8.8.2; Progress fixes are available in WS_FTP Server 2020.0.4 (8.7.4) and 2022.0.2 (8.8.2). Researchers estimated roughly 2,900 internet-exposed WS_FTP hosts could be reachable, and warned that URL-only WAF rules may not detect exploitation because the IIS module processes requests throughout the AHT application; defenders should patch and inspect multipart request content for malicious serialized payloads.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Searchlight Cyber published research on CVE-2023-40044, detailing an unauthenticated RCE path in the WS_FTP Ad Hoc Transfer component. The research identified attacker-controlled BinaryFormatter deserialization in the MyFileUpload.UploadModule and estimated roughly 2,900 internet-exposed WS_FTP hosts could be reachable.
An independent researcher publicly released a proof of concept for CVE-2023-40044 on Twitter/X after Progress released its patch.
Progress addressed CVE-2023-40044 in WS_FTP Server 2020.0.4 (8.7.4) and WS_FTP Server 2022.0.2 (8.8.2). The flaw allows unauthenticated command execution through unsafe deserialization in the Ad Hoc Transfer application.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.