LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-0669: Fortra GoAnywhere MFT Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 10, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-0669 to its Known Exploited Vulnerabilities catalog on Feb 10, 2023, with a federal patch deadline of Mar 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

CVE-2023-0669 is a pre-authentication remote code execution vulnerability in Fortra GoAnywhere MFT (formerly HelpSystems). It stems from insecure handling of data in the License Response Servlet and can let an unauthenticated attacker run code on the affected system. Because GoAnywhere MFT is commonly used for managed file transfers of sensitive business data, successful exploitation can give attackers a foothold for further compromise, data theft, or ransomware deployment. Public reporting confirms known ransomware use of this vulnerability, so organizations running the product should treat it as high priority and confirm all details against the vendor advisory.

How it works

The underlying weakness is CWE-502, Deserialization of Untrusted Data. According to the CISA summary, Fortra GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. In this class of flaw, the application accepts serialized data from an untrusted source and reconstructs objects from it without sufficient validation or type restrictions. An attacker who can reach the servlet can supply a crafted object that, when deserialized, triggers code execution under the privileges of the GoAnywhere process. Because the issue is pre-authentication, no valid credentials are required. Exact request formats, gadget chains, or other exploit mechanics are not detailed here and must be confirmed against the vendor advisory; defenders should treat any unsolicited traffic to the License Response Servlet as potentially malicious.

Am I affected? How to find it in your systems

Fortra GoAnywhere MFT is typically deployed as an enterprise managed file transfer platform, often on dedicated servers or virtual machines that handle inbound and outbound secure transfers. It may be internet-facing or reachable from partner networks. To inventory:

How to remediate

The CISA-required action is to apply updates per vendor instructions. Obtain and install the security updates published by Fortra for CVE-2023-0669 as soon as possible. After patching:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities with known ransomware use frequently lead to data breaches or encryption events. If you discover evidence of exploitation, treat the incident as a potential compromise: isolate affected systems, preserve logs and memory images, and follow your incident-response plan. As a quick personal check, you can run a free exposure scan of your email address against known breach data to see whether credentials or other information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortra · GoAnywhere MFT
WeaknessCWE-502
Added to CISA KEVFeb 10, 2023
Federal patch deadlineMar 3, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities