QID 27393
Date Published: 2023-05-24
QID 27393: Progress WS_FTP Privilege Escalation Vulnerability
WS-FTP Server, a popular FTP server for Microsoft Windows platforms, is vulnerable, it is possible for a host administrator to elevate their privileges on the WS_FTP Server system through the administrative interface due to insufficient authorization controls applied on user modification workflows.
Affected Versions:
WS_FTP Server versions prior to 8.8
QID Detection Logic
This QID checks for Vulnerable version of progress WS_FTP Server
Successfully exploiting this issue allows privilege escalation
Solution
Upgrade to WS_FTP Server 8.8 or later. Please refer to WS_FTP Server for more information.
Vendor References
CVEs related to QID 27393
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WS-FTP-Server-Critical-Security-Product-Alert-Bulletin-January-2023 |
|