>

CrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer

On April 19-20, 2024, CrushFTP shipped emergency fixes for CVE-2024-4040 — an unauthenticated escape from the virtual file system sandbox that exposed arbitrary host files, including the credential-stuffed configuration that anchors enterprise partner integrations. Exploitation followed within days, CISA listed it April 30, and a chaotic trail of interim builds left customers arguing about version numbers mid-fire. This account covers the traversal-to-escape chain, the mainserv credential hunt, and the hard lessons of small-vendor emergency patching.

Continue ReadingCrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer
>