3rd Party Risk Management , Critical Infrastructure Security , Cybercrime
Alert: Attackers Actively Exploiting WS_FTP Vulnerabilities
Cybersecurity Officials Recommend Immediate Patching to Fix Serious FlawsWarnings are being sounded to large enterprises, including government and educational organizations, to immediately update widely used FTP software amid active attacks.
See Also: Gartner Guide for Digital Forensics and Incident Response
Multiple exploitable flaws exist in numerous versions of WS_FTP Server, built by Progress Software. One of the most serious is present in WS_FTP Server versions prior to 8.7.4 and 8.8.2, in a module for sending files person-to-person. The module, marketed by Progress Software as the Ad Hoc Transfer Module, is vulnerable to an attack that converts a hypertext transfer protocol message into a malicious object that can execute arbitrary code, a technique known as deserialization.
Australian cybersecurity firm Assetnote, which identified the deserialization flaw, said Saturday it had identified "about 2,900 hosts on the internet that are running WS_FTP and also have their webserver exposed, which is necessary for exploitation." Most of the instances "belong to large enterprises, governments and educational institutions."
"We discovered that the vulnerability could be triggered without any authentication, and it affected the entire Ad Hoc Transfer component of WS_FTP," Assetnote said. "It was a bit shocking that we were able to reach the deserialization sink without any authentication," allowing for arbitrary code exploitation.
Progress Software patched eight flaws on Wednesday and recommends all users update. "Upgrading to a patched release, using the full installer, is the only way to remediate this issue," the Burlington, Massachusetts-based vendor said in a Wednesday security alert. "There will be an outage to the system while the upgrade is running."
The updates include a patch for the .NET deserialization vulnerability, tracked as CVE-2023-40044, through which attackers can remotely execute arbitrary code.
The .NET deserialization flaw "is trivially exploitable," Caitlin Condon, head of vulnerability research at Rapid7, told Information Security Media Group.
Proof-of-concept code for exploiting CVE-2023-40044 became public Friday, Rapid7 said. By Saturday, the firm reported seeing "what appears to be exploitation of one or more recently disclosed WS_FTP vulnerabilities in multiple customer environments." Since Sunday, it has been tracking a second campaign targeting one or more of the WS_FTP vulnerabilities, reporting that attempted "mass exploitation" of the flaws might already be well underway.
Progress Software in an emailed statement said it is "disappointed in how quickly third parties released a proof of concept." The published exploit "has given cyber criminals a tool to attempt attacks against our customers. We are encouraging all WS_FTP server customers to patch their environments as quickly as possible."*
The U.S. Health Sector Cybersecurity Coordination Center, or HC3, in a Friday alert, said it "strongly encourages all users to follow the manufacturer's recommendation and upgrade to the highest version available - 8.8.2 - to prevent any damage from occurring."
"If you are using the Ad Hoc Transfer module in WS_FTP Server and are not able to update to a fixed version, consider disabling or removing the module," Rapid7 said. The firm has also updated its Velociraptor open source security monitoring software tool's library with a forensic artifact that allows users to review Microsoft Internet Information Services server logs for signs of exploitation.
Disabling the Ad Hoc Transfer module won't mitigate the seven other vulnerabilities patched via the latest versions of WS_FTP Server. Another critical flaw is CVE-2023-42657, a directory traversal vulnerability. "If successfully exploited, an attacker could leverage this to perform file operations - delete, rename, rmdir, mkdir - on files and folders that are outside of the authorized WS_FTP path," HC3 said. "Additionally, the attacker could escape the WS_FTP server file structure and perform the same operations on the operating system."
Target: Secure File Transfer Software
Software used to securely transfer files continues to be a top target for extortionists. Assetnote said it found the vulnerabilities in WS_FTP after proactively reviewing a client's attack surface in light of such attacks.
The Clop - aka Cl0p - ransomware group in particular continues to find and exploit vulnerabilities in widely used file transfer software, starting with Accellion's legacy File Transfer Appliance software in 2021 (see: Accellion Agrees to $8.1 Million Breach Settlement).
Since then, Clop has launched similar campaigns targeting SolarWinds Serv-U, Fortra's GoAnywhere MFT and more recently MOVEit, made by WS_FTP developer Progress Software (see: Data Breach Toll Tied to Clop Group's MOVEit Attack Surges).
Earlier this year, Dylan Pindur of Assetnote reported a critical vulnerability in Citrix ShareFile storage zones controller, or SZC, in the cloud-based secure file sharing and storage service also known as Citrix Content Collaboration, to the vendor. The vulnerability - CVE-2023-24489 - can be exploited to steal data and remotely execute code. Citrix released ShareFile SZC version 5.11.24 to patch the flaw on May 11. It notified customers directly about the vulnerability and worked with them to get it installed.
By the time it issued a public alert about the flaw on June 13, Citrix had reported 83% of customers had installed the patch. Also by that time, it said, "all unpatched SZC hosts were blocked from connecting to the ShareFile cloud control plane, making unpatched SZC hosts unusable with ShareFile," thus restricting the impact of any exploit to only an unpatched customer's environment.
On Aug. 16, the U.S. Cybersecurity and Infrastructure Security Agency warned that the Citrix ShareFile vulnerability was being actively exploited by attackers.
Security experts have warned all organizations that use secure file transfer tools to review their documentation to identify how such software can be locked down. Encrypting data, using strong access controls and leaving files on such systems for as little time as possible are just some of the cyber hygiene practices organizations should follow, Teresa Walsh, chief intelligence officer at FS-ISAC, which is the financial services industry's information sharing and analysis center, recently told ISMG (see: Lessons to Learn From Clop's MOVEit Supply Chain Attacks).
*Update Oct. 2, 2023 17:51 UTC: Adds statement from Progress Software
*Update Oct. 3, 2023 10:01 UTC: Adds statement from Citrix ShareFile