Known MFT exploits

A handful of MFT products have produced the most impactful file-transfer exploits, several used in widespread extortion campaigns against the many organizations that ran the affected appliance. Each pairs an unauthenticated entry point with escalation to data access or code execution.

Subtopics#

  • MOVEit Transfer: pre-auth SQL injection to data theft and RCE.
  • GoAnywhere MFT: admin auth bypass and deserialization RCE.
  • Serv-U: traversal file disclosure and remote code execution.
  • CrushFTP: authentication bypass to admin and file access.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more