CVE-2023-6218
MOVEit Transfer Group Admin Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.
En las versiones de Progress MOVEit Transfer lanzadas antes de 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), se ha identificado una ruta de escalada de privilegios asociada con los administradores de grupo. Es posible que un administrador de grupo eleve los permisos de los miembros de un grupo al rol de administrador de la organización.
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-20 CVE Reserved
- 2023-11-29 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (2)
URL | Tag | Source |
---|---|---|
https://www.progress.com/moveit | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-November-2023 | 2023-12-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | <= 2021.1.0 Search vendor "Progress" for product "Moveit Transfer" and version " <= 2021.1.0" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2022.0.0 < 2022.0.9 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2022.0.0 < 2022.0.9" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2022.1.0 < 2022.1.10 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2022.1.0 < 2022.1.10" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2023.0.0 < 2023.0.7 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2023.0.0 < 2023.0.7" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Transfer Search vendor "Progress" for product "Moveit Transfer" | >= 2023.1.0 < 2023.1.2 Search vendor "Progress" for product "Moveit Transfer" and version " >= 2023.1.0 < 2023.1.2" | - |
Affected
|