March 13, 2024, 2:40 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

CVE-2024-25153, a critical Unsafe File Upload and Directory Traversal vulnerability in Fortra FileCatalyst, allows a remote unauthenticated attacker to gain Remote Code Execution (RCE) on a web server. This affects Fortra FileCatalyst Workflow 5.x before 5.1.6 Build 114.


We have created a full proof-of-concept exploit for this vulnerability, which can be found at GitHub below.


 GitHub: https://github.com/nettitude/CVE-2024-25153


Fortra FileCatalyst is an enterprise managed file transfer (MFT) solution which consists of several components – FileCatalyst Direct, Workflow, and Central. …

attacker build can code code execution concept critical cve directory directory traversal exploit file file upload forensics fortra found proof proof-of-concept rce remote code remote code execution server unauthenticated upload vulnerability web web server workflow

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, VA, Arlington (1550 Crystal Dr Suite 300) non-client

Invoice Compliance Reviewer

@ AC Disaster Consulting | Fort Myers, Florida, United States - Remote

Technical Program Manager II - Compliance

@ Microsoft | Redmond, Washington, United States

Head of U.S. Threat Intelligence / Senior Manager for Threat Intelligence

@ Moonshot | Washington, District of Columbia, United States

Customer Engineer, Security, Public Sector

@ Google | Virginia, USA; Illinois, USA