Description
WS_FTP Ad Hoc Transfer (WS_FTP) is an IIS data transfer module. WS_FTP WS_FTP uses .NET deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data.
Remediation
Upgrade to the latest version of WS_FTP
References
WS_FTP Server Critical Vulnerability - (September 2023)
RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules (CVE-2023-40044)
Related Vulnerabilities
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-14540)
WordPress 6.1.x Multiple Vulnerabilities (6.1 - 6.1.4)
Oracle Access Manager 'opensso' Deserialization RCE (CVE-2021-35587)
OpenCms Solr XML External Entity (XXE) vulnerability
Deserialization of Untrusted Data (Java JSON Deserialization) Genson