HomeCyber BalkansProgress has fixed a new flaw in MOVEit File Transfer that allows...

Progress has fixed a new flaw in MOVEit File Transfer that allows privilege escalation

Published on

spot_img

Progress, the company responsible for maintaining the security of its MOVEit Transfer product, has recently released a critical security alert regarding a newly identified vulnerability. This flaw, known as CVE-2024-6576, has been deemed a high-severity issue, with a CVSS score of 7.3, highlighting the significant risk posed to users.

The vulnerability, detected in the SFTP module of MOVEit Transfer, originates from faulty authentication mechanisms that could potentially enable malicious actors to escalate their privileges. Several versions of the MOVEit Transfer software are impacted by this issue, including versions ranging from 2023.0.0 to 2023.1.7 and 2024.0.0 to 2024.0.3.

To address this security risk, Progress strongly advises all affected customers to upgrade to the latest patched versions of the software. The company has provided a table outlining the fixed versions available for download, including MOVEit Transfer 2024.0.3, 2023.1.7, and 2023.0.12, each accompanied by installation guides and release notes.

In order to upgrade, customers are instructed to log in to the Progress Community’s Download Center using their Progress ID credentials, select the appropriate asset from the “My Active” tab list, click the download link under the “Related Products & Downloads” section, and download the fixed version as specified in the table provided. Should customers encounter any issues or have questions, they are encouraged to open a new Technical Support case through the Progress Community platform. Customers without a current maintenance agreement are advised to reach out to the Progress Renewals team or their designated Progress partner account representative for assistance.

It is essential to note that the only way to address this vulnerability is by upgrading to a patched release using the full installer, which may result in a temporary system outage during the upgrade process. However, customers utilizing the Cloud service need not take any action, as the cloud service has already been updated to the patched version.

In conclusion, the timely and thorough response of Progress to this security vulnerability underscores the company’s commitment to ensuring the safety and integrity of its products. By promptly addressing and remedying such critical issues, Progress demonstrates its dedication to maintaining the trust and security of its customers.

Source link

Latest articles

North Korean Hackers Target Crypto Firms Using ClickFix and Zoom Tactics

A recently released report from Arctic Wolf has unveiled a significant cyber theft campaign...

BlueNoroff Launches Fileless PowerShell Attack in AI-Driven Zoom Phishing Campaign

In a sophisticated cyber campaign, the North Korean state-sponsored group known as BlueNoroff has...

VECT 2.0 Ransomware Permanently Destroys Files Larger than 131KB on Windows, Linux, and ESXi

Threat hunters have raised alarms regarding a new cybercriminal operation named VECT 2.0. Unlike...

Cybersecurity Professionals Feel Underappreciated

Growing Dissatisfaction Among Cybersecurity Professionals: A Call for Recognition and Support A recent report by...

More like this

North Korean Hackers Target Crypto Firms Using ClickFix and Zoom Tactics

A recently released report from Arctic Wolf has unveiled a significant cyber theft campaign...

BlueNoroff Launches Fileless PowerShell Attack in AI-Driven Zoom Phishing Campaign

In a sophisticated cyber campaign, the North Korean state-sponsored group known as BlueNoroff has...

VECT 2.0 Ransomware Permanently Destroys Files Larger than 131KB on Windows, Linux, and ESXi

Threat hunters have raised alarms regarding a new cybercriminal operation named VECT 2.0. Unlike...