Progress ShareFile external security threat

I guess threat intel does not come more unpolished than this. Progress is reporting on a “credible external security threat” and recommending customers to shutdown their Progress ShareFile Storage Zones Controller servers. Full story on Progress urges ShareFile admins to shut down servers over “credible” threat

I guess we are still waiting on an update from Progress. Both the public status page and the Reddit thread do not mention any updates since the 10th.

1 Like

This comment seems noteworthy:

I spoke with my account engineer yesterday when we got the email. This is a reaction to the April CVEs (auth bypass and RCE being chained together). While the ‘fix’ was updating your version, there was ‘evidence’ that the attack still worked and is being actively exploited. Given the clop attack on moveit and the slowness Process showed they want to be ahead of it and limit exposure. Reading between the ae’s line I am thinking a number of clients and possibly host storage zones have been popped and Process need to work out a fix but can’t risk the rate of exposure hence the ‘cut the power to the building’ email

Bleeping Computer has an update on this story: “Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Turns out this is an authenticated path traversal vulnerability. There are updates available (version 5.12.5 and 6.0.2) behind a Progress login. There is no CVE number assigned (yet), which makes tracking this harder for the time being. No public statement either, as this was communicated to customers by e-mail.

1 Like