Subj : The makers of MOVEit have patched another major security flaw To : All From : TechnologyDaily Date : Fri Sep 29 2023 15:15:04 The makers of MOVEit have patched another major security flaw Date: Fri, 29 Sep 2023 13:56:59 +0000 Description: The WS_FTP Server product was found to be vulnerable in multiple ways, with two flaws being labeled as critical. FULL STORY ====================================================================== The company behind the now-famous (for all the wrong reasons) MOVEit managed file transfer software has warned its clients that a different product - WS_FTP Server, also carries a couple of high-severity flaws that can be exploited in malware hacks. In an advisory, Progress said WS_FTP carried eight vulnerabilities, two of which were labeled as critical. One is tracked as CVE-2023-40044 (severity rating 10/10), while the other is tracked as CVE-2023-42657 (9.9/10). These vulnerabilities allow threat actors to run a range of malicious activities, including remote code execution. "Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system," Progress said in the advisory. Patching the flaw The worst part is - these flaws dont even require user interaction, as the company adds, "We have addressed the vulnerabilities above and the Progress WS_FTP team strongly recommends performing an upgrade." "We do recommend upgrading to the most highest version which is 8.8.2. Upgrading to a patched release, using the full installer, is the only way to remediate this issue. There will be an outage to the system while the upgrade is running." There is also a way to remove and disable the vulnerable WS_FTP Server Ad Hoc Transfer Module, for those who cannot patch right away, or dont really use the service. The details can be found here . Progress is the company behind MOVEit, a managed file transfer solution that was compromised by ransomware actors Clop , resulting in a major data theft affecting more than 2,000 firms, so far. As for WS_FTP Server, we dont know if the flaws were used by any hackers in the meantime, but the product was being used by thousands of IT teams, according to Progress. Via BleepingComputer More from TechRadar Pro Millions of newborn child registry data entries stolen by another MOVEit hack Here's a list of the best firewalls today These are the best malware removal tools right now ====================================================================== Link to news story: https://www.techradar.com/pro/security/the-makers-of-moveit-have-patched-anoth er-major-security-flaw --- Mystic BBS v1.12 A47 (Linux/64) * Origin: tqwNet Technology News (1337:1/100) .