CISA Urges Patching of Actively Exploited Citrix Bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-24489 | Unauthenticated RCE in Citrix ShareFile Storage Zones Controller (CVE-2023-24489) CVE-2023-24489 is an improper access control flaw (CWE-284), rated critical at CVSS 9.8, in the customer-managed Citrix Content Collaboration ShareFile storage zones controller. It can be triggered remotely over the network by an unauthenticated attacker with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N). A successful attack allows the attacker to remotely compromise the customer-managed storage zones controller — described in vendor-adjacent coverage as remote code execution — giving control of the server that stores and syncs that organization's ShareFile files. Only organizations that self-host customer-managed storage zones controllers are affected; the vendor-managed (cloud) ShareFile service is not listed as affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2023-08-16, EPSS assigns a 97.3% probability of exploitation within 30 days (100th percentile), and the vendor urged customers to shut down or take unpatched controllers offline; ransomware use is not yet confirmed. Do: Apply the fix specified in the Citrix/ShareFile security bulletin by upgrading every customer-managed storage zones controller to the vendor's patched release, and follow vendor guidance to shut down or take offline any controller that cannot be patched immediately. Check whether controllers are internet-exposed and hunt for signs of compromise (unexpected files, processes, or webshells on storage zones), since the flaw is in the KEV catalog and ransomware use has not been ruled out. | 9.8 | 97% | KEV |
| moderate≈ thousands of internet-exposed customer-managed storage zone controllers (order-of-magnitude estimate) |
Full article384 words · extracted from infosecurity-magazine.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that a Citrix flaw patched in May is being actively exploited in the wild.
CVE-2023-24489 was added to the agency’s Known Exploited Vulnerabilities Catalog yesterday, with CISA warning it poses “significant risks to the federal enterprise.”
The flaw is described as an improper access control vulnerability in Citrix ShareFile (aka Citrix Content Collaboration). If exploited, it “could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller,” CISA said.
Citrix released an advisory on the critical severity bug, which has a CVSS score of 9.1, on June 13. However, the vulnerability was patched in May by ShareFile. The company contacted Infosecurity to confirm that, by May 11, over 83% of customers had patched their environments, before the incident was made public. It claimed the incident affected less than 3% of its install base.
"When this vulnerability was discovered, we worked with and notified impacted customers in advance of the announced CVE to update to the latest version of our software to assure the safety of their data," it added. "Our control plane is no longer connected to any ShareFile StorageZones Controller (SZC) that is not patched."
Read more on flaws in file sharing software: Clop Ransom Gang Breaches Big Names Via MOVEit Flaw
Citrix Content Collaboration is software that allows enterprise file sync and sharing. Its storage zones controller feature enables users to extend these file sharing capabilities to private data storage in order to meet regulatory requirements.
“The storage zones that you maintain can reside in your on-premises single-tenant storage system or in supported third-party cloud storage. This includes Amazon S3 and Windows Azure,” Citrix explains.
“Storage zones controller also provides users with secure access to SharePoint sites and network file shares through storage zone connectors. Storage zone connectors enable you to provide secure mobile access to data residing behind your corporate firewall without the need to migrate data to the cloud.”
File sharing services have become a popular target for ransomware groups over recent years, with the Clop group in particular exploiting zero-day vulnerabilities in MOVEit, and earlier in Accellion and GoAnywhere products, to devastating effect.
That’s why CISA demands all federal civilian agencies patch the vulnerability by September 6. Private enterprises are encouraged to follow suit.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-patching-actively-exploited/