PT-2025-11688 · Ipswitch · Moveit Transfer

Published

2025-03-19

·

Updated

2025-07-31

·

CVE-2025-2324

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MOVEit Transfer versions 2023.1.0 through 2023.1.11 MOVEit Transfer versions 2024.0.0 through 2024.0.7 MOVEit Transfer versions 2024.1.0 through 2024.1.1
Description The issue is related to Improper Privilege Management for users configured as Shared Accounts in the SFTP module of MOVEit Transfer, allowing Privilege Escalation.
Recommendations For MOVEit Transfer versions 2023.1.0 through 2023.1.11, update to version 2023.1.12 or later. For MOVEit Transfer versions 2024.0.0 through 2024.0.7, update to version 2024.0.8 or later. For MOVEit Transfer versions 2024.1.0 through 2024.1.1, update to version 2024.1.2 or later.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-2324

Affected Products

Moveit Transfer