CVE-2025-2324
published 2025-03-19CVE-2025-2324: Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.26%
18.3th percentile
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| progress | moveit_transfer | >= 2023.1.0 < 2023.1.12 | 2023.1.12 |
| progress | moveit_transfer | >= 2024.0.0 < 2024.0.8 | 2024.0.8 |
| progress | moveit_transfer | >= 2024.1.0 < 2024.1.2 | 2024.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Progress MOVEit Transfer up to 2023.1.11/2024.0.7/2024.1.1 SFTP privileges management (Nessus ID 326457)
vuldb·2026-07-14·CVSS 8.8
CVE-2025-2324 [HIGH] Progress MOVEit Transfer up to 2023.1.11/2024.0.7/2024.1.1 SFTP privileges management (Nessus ID 326457)
A vulnerability has been found in Progress MOVEit Transfer up to 2023.1.11/2024.0.7/2024.1.1 and classified as critical. This affects an unknown part of the component SFTP Module. Performing a manipulation results in improper privilege management.
This vulnerability was named CVE-2025-2324. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-r985-fv8x-vqj3: Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalat
ghsa_unreviewed·2025-03-19
CVE-2025-2324 [MEDIUM] CWE-269 GHSA-r985-fv8x-vqj3: Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalat
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-19
Published