{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-40044",
  "revision": 1,
  "title": "WS_FTP Server — the transfer module that deserializes",
  "summary": "The ad hoc transfer module in WS_FTP Server deserializes data it has not verified, so an attacker who never logged in runs commands on the host. Versions before 8.7.4 and 8.8.2 are affected, and ransomware crews used it.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.9015,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2023-10-05",
    "prerequisites": "Network access to the transfer server."
  },
  "remediation": {
    "patch_available": true,
    "workaround_available": true,
    "fixed_in": [
      "WS_FTP Server >= 8.7.4",
      "WS_FTP Server >= 8.8.2"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade WS_FTP Server to 8.7.4 or 8.8.2. Where that must wait, turn off the ad hoc transfer module — the vendor names it as the affected component.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-40044",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-40044",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-40044",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40044",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023"
    },
    {
      "type": "exploit",
      "url": "http://packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-Unauthenticated-Remote-Code-Execution.html"
    },
    {
      "type": "exploit",
      "url": "https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044"
    }
  ],
  "published_at": "2023-09-27T15:18:57.307Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "progress",
    "ws-ftp",
    "file-transfer",
    "deserialization",
    "ransomware",
    "kev"
  ]
}
