Progress Software has released critical security updates that address a serious vulnerability in MOVEit Transfer, a widely used file transfer solution for businesses.

The vulnerability, tracked as CVE-2025-10932, has a CVSS score of 8.2/10 and affects the AS2 module in multiple versions of the product. The vulnerability could allow attackers to disrupt service availability by exhausting system resources.
The vulnerability exists in versions 2025.0.0 to 2025.0.2, 2024.1.0 to 2024.1.6, and 2023.1.0 to 2023.1.15. With a network-accessible attack vector that does not require authentication or user interaction, organizations using the affected versions face significant risks.
See also: Hackers exploit RCE vulnerability via Windows LNK files
Progress MOVEit Transfer: Vulnerability
The vulnerability results from inadequate resource consumption controls (category CWE-400). This category of vulnerabilities allows attackers to overload systems, forcing excessive resource allocation and leading to a denial-of-service condition that affects legitimate business operations.
Progress has distributed hotfixes that require IP address whitelisting for the AS2 module, creating a protective barrier against unauthorized access. Organizations should take immediate action based on their specific deployment model.

Enterprises not using the AS2 module with MOVEit products can remove vulnerable endpoints as a temporary solution. Administrators should delete the AS2Rec2.ashx and AS2Receiver.aspx files from the C:\MOVEitTransfer\wwwroot directory. This simple approach does not require a server restart and maintains continuity until permanent fixes are implemented.
See also: RediShell RCE vulnerability: Over 8,500 vulnerable Redis instances
For organizations that actively use AS2 functionality , applying the hotfix is required . After updating to the MOVEit Transfer 2025.0.3, 2024.1.7, or 2023.1.16 patch releases , administrators must configure IP whitelist rules for authorized trading partners. This requires logging into MOVEit Transfer as an administrator, navigating to Settings, accessing Security Policies, and configuring Remote Access Rules to restrict access to the AS2 module to trusted partner IP addresses
Progress has made the fixes available through the Download Center for customers with current maintenance agreements. The availability of fixes covers three major version lines, ensuring that organizations can update within their supported product branch. Customers without active maintenance agreements should contact Progress renewal services or their designated partner account representative.
See also: Multiple Jenkins vulnerabilities: SAML Authentication Bypass

Importantly, Progress MOVEit Cloud users do not require immediate action as the cloud infrastructure has already been upgraded to patched versions. However, on-premises installations require immediate attention. Organizations running MOVEit Transfer versions outside of these active branches should prioritize upgrading to current supported versions or implementing the temporary workaround of removing AS2 endpoints.
The high CVSS score reflects the severity of this vulnerability and the potential business impact of service interruptions. Rapid implementation of fixes is a critical priority for security teams managing file transfer infrastructure across their enterprise environment.
