CVE-2023-6218 HIGH

CVE-2023-6218: MOVEit Transfer Group Admin Privilege Escalation

Vendor Progress Software Corporation
Product MOVEit Transfer
Weakness CWE-269
Published November 29, 2023
Last update August 2, 2024

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified.  It is possible for a group administrator to elevate a group members permissions to the role of an organization administrator.

Key dates

02Disclosure timeline

November 29, 2023 CVE published
August 2, 2024 Record updated