LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-4040: CrushFTP VFS Sandbox Escape Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 24, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 1, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-4040 to its Known Exploited Vulnerabilities catalog on Apr 24, 2024, with a federal patch deadline of May 1, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

CVE-2024-4040 is a sandbox escape vulnerability in CrushFTP that lets a remote attacker break out of the product's virtual file system (VFS). Because CrushFTP is commonly used to provide managed file transfer and remote access to internal storage, a successful escape can give an attacker broader access to the host and any data the service can reach. Confirm all product-specific details against the vendor advisory before acting.

CISA notes that the vulnerability is unspecified beyond the VFS escape and requires organizations to apply the vendor's mitigations or discontinue use if those mitigations are unavailable. No ransomware use is documented for this CVE.

How it works

The weakness is catalogued as CWE-1336. In this class of flaw, insufficient isolation of the virtual file system allows an attacker who can interact with the CrushFTP service to leave the intended sandbox. Once outside the VFS, the attacker may reach files, directories, or system resources that the service account can access. Public detail on the precise trigger is limited; treat any remote interaction with the CrushFTP interface as potentially capable of abuse until the vendor advisory is reviewed. Do not assume authentication is required or that only certain endpoints are affected—confirm those points with the vendor.

Am I affected? How to find it in your systems

CrushFTP typically runs as a dedicated file-transfer server on Windows or Linux hosts, often exposed to the internet or to partner networks for SFTP, FTPS, HTTP, or HTTPS access. Inventory steps:

Version and configuration details that determine exposure are not supplied here; compare every discovered instance against the exact versions and settings listed in the vendor advisory. Telemetry signs of exploitation are also unspecified; look for unexpected file-system access outside the configured VFS roots, anomalous process launches under the CrushFTP service account, or sudden spikes in administrative or file-listing activity. Correlate those events with authentication logs and any web or protocol access logs the product generates.

How to remediate

Apply the vendor update or mitigation named in the official CrushFTP advisory as the primary remediation. After patching, verify that the service restarts cleanly and that the VFS isolation is restored. Additional hardening for this class of sandbox-escape issue includes:

Re-test access controls after the change and document the new baseline.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls:

If your data may have been exposed

Actively exploited sandbox-escape vulnerabilities can lead to unauthorized access and data theft. If you believe an attacker may have escaped the VFS on your CrushFTP instance, treat the host and any reachable storage as potentially compromised: isolate the system, preserve logs, and begin incident-response procedures. You can also run a free exposure scan of your email addresses against known breach data to determine whether credentials or personal information associated with your organization have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCrushFTP · CrushFTP
WeaknessCWE-1336
Added to CISA KEVApr 24, 2024
Federal patch deadlineMay 1, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities