An improper authentication vulnerability can lead to privilege escalation
Summary
An improper authentication vulnerability can lead to privilege escalation
Affected platforms
The following platforms are known to be affected:
Progress (formerly Ipswitch) MOVEit Transfer
Threat details
Introduction
Progress (formerly Ipswitch) has released a security update for a vulnerability in the SFTP module of the MOVEit Transfer application. MOVEit is a managed secure file transfer tool.
CVE-2024-6576 has a CVSSv3 score of 7.3 and can lead to privilege escalation in MOVEit Transfer.
Remediation advice
Affected organisations are encouraged to review the Progress Community MOVEit Transfer Critical Security Alert Bulletin July 2024 - CVE-2024-6576 (applies to MOVEit Transfer) and apply updates as soon as practicable.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 1 August 2024 2:05 pm