Description
WS_FTP Ad Hoc Transfer (WS_FTP) is an IIS data transfer module. WS_FTP WS_FTP uses .NET deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data.
Remediation
Upgrade to the latest version of WS_FTP
References
WS_FTP Server Critical Vulnerability - (September 2023)
RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules (CVE-2023-40044)