ZeroHour

CVE-2021-22941

KEV ransomwarelarge

Unauthenticated Remote Compromise of Citrix ShareFile Storage Zones Controller

CISA: Citrix ShareFile Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2021-22941 is an improper access control flaw (CWE-284) in Citrix ShareFile storage zones controller that allows an unauthenticated attacker to remotely compromise the controller over the network with no privileges or user interaction required (CVSS 9.8 critical). Any organization running a storage zones controller version before 5.11.20 is affected, and because these controllers handle file storage and transfer, a successful attack exposes both the server and the data it hosts. A compromised controller gives an attacker a foothold in the enterprise network, which is consistent with the flaw's known use in ransomware operations. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 with ransomware use explicitly flagged, and its 53.6% EPSS score (99th percentile) indicates a high near-term probability of exploitation; related reporting on access brokers such as the Gold Melody group selling network access to ransomware operators underscores the active threat. Defenders should treat this as actively exploited rather than theoretical.

What to do: Upgrade storage zones controller to version 5.11.20 or later following Citrix's update instructions, prioritizing internet-exposed controllers since exploitation requires no credentials. Given confirmed ransomware use, hunt for signs of compromise on currently deployed controllers (unexpected processes, new or modified scheduled tasks and accounts, unfamiliar files) before and after patching. Restrict controller exposure to the minimum necessary network paths and monitor for follow-on lateral movement.

Affected
Citrix ShareFile Storage Zones Controllerall versions before 5.11.20
Estimated exposure
largelikely tens of thousands of enterprise deployments (order-of-magnitude estimate; no official install counts) — Citrix does not publish controller install counts, so the estimate is based on ShareFile's broad adoption among tens of thousands of businesses and the typical enterprise pattern of deploying one or more on-premises storage zones…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CISA Known Exploited Vulnerability
Affected
Citrix ShareFile
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
citrix
Products
sharefile storagezones controller
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news