Breaking
SecurityDeveloping Story

ShareFile Patch Addresses Path Traversal

Progress confirms a high-severity flaw in Storage Zone Controllers necessitated a temporary service shutdown for customers.

··1 month ago·2 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

Organizations managing their own data infrastructure through released versions of ShareFile faced a sudden operational disruption last week. Following reports of a credible external threat, Progress issued an urgent advisory that prompted users to immediately shut down their Windows servers while the company scrutinized the security of its platform.

Identifying the Vulnerability

The investigation into the security warning uncovered a high-severity path traversal vulnerability. This security gap spans multiple iterations of the software, specifically impacting all 5.x and 6.x versions of the ShareFile Storage Zone Controller.

An authenticated administrative user can read arbitrary files accessible to the application's service account, write threat actor-controlled content to arbitrary directories or enumerate the server filesystem layout.

Progress, via an email update provided to BleepingComputer.

Immediate Patching Requirements

Progress has responded by releasing updated versions of its software to close the security gap. To restore standard operations, administrators must transition their systems to the patched environments. Once these updates are applied, customers are permitted to bring their Storage Zone Controllers back online.

  • Affected software covers all 5.x and 6.x versions of the ShareFile Storage Zone Controller.
  • Updates have been issued for versions 5.12.5 and 6.0.2.
  • The reserved CVE identifier is scheduled for publication in two weeks.

Infrastructure Risk Assessment

Because Storage Zone Controllers are customer-managed Windows servers, they provide a bridge between local storage and cloud-based authentication services. This architecture means the servers host the actual files being shared, making them a high-value target for actors interested in data theft attacks. Despite the severity of the flaw, the company maintains that its investigation has not surfaced evidence of actual exploitation or breach.

As the industry navigates these vulnerabilities, the reliance on customer-managed components highlights a broader challenge for enterprise security teams. The lag time between identifying a vulnerability and the public disclosure of a CVE identifier can create a window where administrators must act on limited technical information to secure their environments. For organizations, this underscores the necessity of maintaining robust, up-to-date patching cycles for all on-premises software that connects to cloud-based services, as these hybrid configurations often represent a complex attack surface that requires constant vigilance.

#sharefile#vulnerability#cybersecurity#enterprise#software

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories