CrushFTP is a file transfer server that supports secure protocols, offers easier configuration, and offers powerful monitoring tools.
It also provides a web interface that allows users to transfer files using a web browser.
A critical vulnerability associated with FileSystem escape has been discovered and addressed in the latest version.
This particular vulnerability allows any user to download system files escaping from the virtual file system present in the CrushFTP application.
Moreover, there have also been reports indicating the exploitation of this vulnerability in the wild by threat actors.
Free Webinar | Mastering WAAP/WAF ROI Analysis | Book Your Spot
No CVE was assigned to this vulnerability at the time of reporting.
Additionally, customers who use Demilitarized Zones (DMZ) in with their CrushFTP instance are not affected by this vulnerability due to the protocol translation system.
According to the reports shared with Cyber Security News, there have been several exploitation attempts over CrushFTP instances owned by multiple U.S. Entities, which are speculated to be an activity of Politically Motivated Intelligence Gathering.
To provide a brief insight, the CrushFTP application is a bundled stand-alone portal executable (PE) that probably doesn’t have a standard installation location.
The application can run on Windows, macOS and Linux and depend on Java.
To prevent the exploitation of this vulnerability, users of CrushFTP are recommended to upgrade to the latest version, v11.1.0, which has a patch for it.
All versions before CrushFTP v9 are affected.
For more information about the changelogs and other information, the CrushFTP wiki page can be viewed.
To update CrushFTP to the latest version v11.1.0 (for Online users), the following steps can be followed:
For Offline users, the below steps can be followed
Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP
.
Hackers have reportedly infiltrated and extracted a vast 82 GB of sensitive data from the Indonesian…
IBM has issued a security bulletin warning of two vulnerabilities in its AIX operating system…
The Apache Software Foundation has issued a security alert regarding a critical vulnerability in Apache…
The Chinese National Internet Emergency Center (CNIE) has revealed two significant cases of cyber espionage…
A critical command injection vulnerability in the popular systeminformation npm package has recently been disclosed, exposing millions…
Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer through…