# CVE-2023-0669 — Fortra Goanywhere MFT

**CISA KEV** · **Ransomware**

> As of 2025-10-21, CVE-2023-0669 is a HIGH-severity vulnerability in Fortra Goanywhere MFT, CVSS v3.1 7.2, EPSS 99.9% (99.9th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2023-02-10), with a US federal remediation deadline of 2023-03-03, and CISA links it to known ransomware campaigns. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2023-0669, most recently “LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)”.

**Last updated:** 2025-10-21

## What is CVE-2023-0669?

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

The record classifies CVE-2023-0669 under weakness class [CWE-502](https://cwe.mitre.org/data/definitions/502.html). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs high-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 1315 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 7.2 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 99.9% probability of exploitation in the next 30 days, higher than 99.9% of all scored CVEs
- **CISA KEV:** Listed since 2023-02-10, federal remediation deadline 2023-03-03 — used in known ransomware campaigns
- **Threadlinqs priority:** 10/10 — CISA lists it as used in ransomware, which Threadlinqs scores at the maximum
- **Published:** 2023-02-06, last modified 2025-10-21

## Is CVE-2023-0669 being exploited?

CISA added CVE-2023-0669 to the Known Exploited Vulnerabilities catalog on 2023-02-10, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2023-03-03 under BOD 22-01. CISA flags the vulnerability as one used in known ransomware campaigns. Weaponised exploit code for CVE-2023-0669 is publicly available. 7 public proof-of-concept repositories are tracked for this identifier. A ProjectDiscovery Nuclei detection template exists (`http/cves/2023/CVE-2023-0669.yaml`). It currently carries a trending score of 45 in the Threadlinqs vulnerability feed.

- [0xf4n9x/CVE-2023-0669](https://github.com/0xf4n9x/CVE-2023-0669) (github)
- [Avento/CVE-2023-0669](https://github.com/Avento/CVE-2023-0669) (github)
- [yosef0x01/CVE-2023-0669-Analysis](https://github.com/yosef0x01/CVE-2023-0669-Analysis) (github)
- [cataliniovita/CVE-2023-0669](https://github.com/cataliniovita/CVE-2023-0669) (github)
- [Griffin-01/CVE-2023-0669](https://github.com/Griffin-01/CVE-2023-0669) (github)
- [zakaria-laouani/cve-2023-0669-simulation](https://github.com/zakaria-laouani/cve-2023-0669-simulation) (github)
- [trickest/cve](https://github.com/trickest/cve/blob/main/2023/CVE-2023-0669.md) (trickest)

## Affected products and versions

- **Fortra**: Goanywhere MFT

Affected software packages:

- `rubygems:metasploit-framework`

## How to fix CVE-2023-0669

The record marks a vendor fix as available for CVE-2023-0669. Patch reference: [https://github.com/rapid7/metasploit-framework/pull/17607](https://github.com/rapid7/metasploit-framework/pull/17607). Because CVE-2023-0669 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2023-03-03. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2023-0669

2 tracked threats in the Threadlinqs corpus reference CVE-2023-0669, either in the campaign’s CVE list or as an indicator on the campaign record.

- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — MEDIUM · 2026-07-22

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, CISA KEV, GitHub Security Advisories, public proof-of-concept repositories, ProjectDiscovery Nuclei. Last verified by Threadlinqs on 2026-07-27. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [my.goanywhere.com — vendor advisory](https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1)

**Exploit and proof of concept**

- [github.com — exploit](https://github.com/rapid7/metasploit-framework/pull/17607)

**Third-party advisory**

- [rapid7.com — third party advisory](https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/)
- [attackerkb.com — third party advisory](https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis)
- [frycos.github.io — third party advisory](https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html)

**Other references**

- [infosec.exchange — media coverage](https://infosec.exchange/@briankrebs/109795710941843934)
- [duo.com — media coverage](https://duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mft)
- [packetstormsecurity.com](http://packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.html)

Canonical: https://intel.threadlinqs.com/cve/CVE-2023-0669
Full detection coverage and IOCs for threats exploiting CVE-2023-0669 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
