CVE-2024-4040
CrushFTP VFS Sandbox Escape Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 May 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 99.54% probability · 100th percentile
- CISA KEV
- Listed 24 April 2024 · due 1 May 2024
- Weakness
- CWE-1336, CWE-94
- Affected
- crushftp/crushftp
- Source
- 430a6cef-dc26-47e3-9fa8-52fb7f19644e
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update&version=34; https://nvd.nist.gov/vuln/detail/CVE-2024-4040
References
- https://github.com/airbus-cert/CVE-2024-4040Exploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/Press/Media Coverage, Third Party Advisory
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=UpdatePatch, Vendor Advisory
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=UpdatePatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/Third Party Advisory
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/Exploit, Issue Tracking
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/Issue Tracking, Patch
- https://github.com/airbus-cert/CVE-2024-4040Exploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/Press/Media Coverage, Third Party Advisory
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=UpdatePatch, Vendor Advisory
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=UpdatePatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/Third Party Advisory
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/Exploit, Issue Tracking
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/Issue Tracking, Patch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4040US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.