HomeUpdatesProgress fixes serious MOVEit Transfer vulnerability

Progress fixes serious MOVEit Transfer vulnerability

Progress Software has released critical security updates that address a serious vulnerability in MOVEit Transfer, a widely used file transfer solution for businesses.

Progress MOVEit Transfer

The vulnerability, tracked as CVE-2025-10932, has a CVSS score of 8.2/10 and affects the AS2 module in multiple versions of the product. The vulnerability could allow attackers to disrupt service availability by exhausting system resources.

The vulnerability exists in versions 2025.0.0 to 2025.0.2, 2024.1.0 to 2024.1.6, and 2023.1.0 to 2023.1.15. With a network-accessible attack vector that does not require authentication or user interaction, organizations using the affected versions face significant risks.

See also: Hackers exploit RCE vulnerability via Windows LNK files

Progress MOVEit Transfer: Vulnerability

The vulnerability results from inadequate resource consumption controls (category CWE-400). This category of vulnerabilities allows attackers to overload systems, forcing excessive resource allocation and leading to a denial-of-service condition that affects legitimate business operations.

Progress has distributed hotfixes that require IP address whitelisting for the AS2 module, creating a protective barrier against unauthorized access. Organizations should take immediate action based on their specific deployment model.

Progress fixes serious MOVEit Transfer vulnerability

Enterprises not using the AS2 module with MOVEit products can remove vulnerable endpoints as a temporary solution. Administrators should delete the AS2Rec2.ashx and AS2Receiver.aspx files from the C:\MOVEitTransfer\wwwroot directory. This simple approach does not require a server restart and maintains continuity until permanent fixes are implemented.

See also: RediShell RCE vulnerability: Over 8,500 vulnerable Redis instances

For organizations that actively use AS2 functionality , applying the hotfix is ​​required . After updating to the MOVEit Transfer 2025.0.3, 2024.1.7, or 2023.1.16 patch releases , administrators must configure IP whitelist rules for authorized trading partners. This requires logging into MOVEit Transfer as an administrator, navigating to Settings, accessing Security Policies, and configuring Remote Access Rules to restrict access to the AS2 module to trusted partner IP addresses

Progress has made the fixes available through the Download Center for customers with current maintenance agreements. The availability of fixes covers three major version lines, ensuring that organizations can update within their supported product branch. Customers without active maintenance agreements should contact Progress renewal services or their designated partner account representative.

See also: Multiple Jenkins vulnerabilities: SAML Authentication Bypass

Progress fixes serious MOVEit Transfer vulnerability

Importantly, Progress MOVEit Cloud users do not require immediate action as the cloud infrastructure has already been upgraded to patched versions. However, on-premises installations require immediate attention. Organizations running MOVEit Transfer versions outside of these active branches should prioritize upgrading to current supported versions or implementing the temporary workaround of removing AS2 endpoints.

The high CVSS score reflects the severity of this vulnerability and the potential business impact of service interruptions. Rapid implementation of fixes is a critical priority for security teams managing file transfer infrastructure across their enterprise environment.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS