QID 378591

Date Published: 2023-06-16

QID 378591: IpSwitch MOVEit Transfer Privilege Escalation and Potential Unauthorized Access Vulnerability

Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment. If you are a MOVEit Transfer customer, it is extremely important that you take immediate action as noted below in order to help protect your MOVEit Transfer environment.

QID Detection Logic: (Authenticated)
This QID checks file version of MOVEit.DMZ.ClassLib.dll to identify the vulnerable versions of the product MOVEit Transfer.

Successful exploitation will lead to privilege escalation and potential unauthorized access

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Currently there is no fix for the vulnerability.

    Workaround:
    Disable all HTTP and HTTPs traffic to your MOVEit Transfer environment. More specifically:

    Modify firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443.
    It is important to note that until HTTP and HTTPS traffic is enabled again:
    Users will not be able to log on to the MOVEit Transfer web UI
    MOVEit Automation tasks that use the native MOVEit Transfer host will not work
    REST, Java and .NET APIs will not work
    MOVEit Transfer add-in for Outlook will not work
    SFTP and FTP/s protocols will continue to work as normal

    Vendor References

    CVEs related to QID 378591

    Software Advisories
    Advisory ID Software Component Link
    © CVE.report 2026 |

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report