Progress Confirms ShareFile Zero-Day Behind Emergency Storage Zone Shutdown, Releases Security Updates

The CyberSec Guru

Progress Confirms ShareFile Zero-Day Behind Emergency Storage Zone Shutdown

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

Progress Software has confirmed that the emergency shutdown request sent to ShareFile customers last week was triggered by a previously undisclosed zero-day vulnerability affecting its Storage Zone Controllers. The company has now released security updates and says organizations can safely bring affected systems back online after patching.

While Progress currently says it has found no evidence that customer data or accounts were compromised, the incident is another reminder that internet-facing enterprise file transfer platforms remain one of the most attractive targets for attackers.

an Unusual Emergency Warning

On July 10, ShareFile customers using Storage Zone Controllers received an email with a subject line that immediately caught administrators’ attention: “Service Disruption. Immediate Action Required.”

Rather than simply advising customers to install an update, Progress instructed organizations to immediately shut down the Windows servers hosting their Storage Zone Controllers. At the same time, the company disabled cloud connectivity for every ShareFile account using those controllers.

The vendor explained only that it had received information about a “credible external security threat” targeting the product. No technical details, CVE identifier, or description of the vulnerability were provided at the time.

Progress also stated that there was no indication of unauthorized access to customer accounts or stored data, but emphasized that disabling cloud access alone was not enough. Customers were specifically instructed to manually power off the affected servers until further notice.

That recommendation alone suggested the problem existed on the servers themselves rather than solely within ShareFile’s cloud infrastructure.

Email sent to ShareFile customers using Storage Zone Controllers
Email sent to ShareFile customers using Storage Zone Controllers

What Are ShareFile Storage Zone Controllers?

Unlike fully cloud-hosted deployments, many organizations use Storage Zone Controllers to keep sensitive files inside their own infrastructure while still relying on ShareFile’s cloud platform for authentication, user management, permissions, auditing, and collaboration.

In this hybrid architecture:

  • User authentication happens through ShareFile’s cloud service.
  • The cloud determines where requested files are stored.
  • Requests are forwarded to the customer’s on-premises Storage Zone Controller.
  • The Windows server retrieves or stores files locally before transferring them to users.

Because these controllers must communicate with both users and ShareFile’s cloud platform, they are commonly deployed as internet-accessible Windows servers.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

That makes them particularly attractive targets for threat actors looking to gain access to valuable corporate documents.

Progress Reveals the Root Cause

Four days after the emergency shutdown notice, Progress disclosed what had actually triggered the incident.

ShareFile Status Page
ShareFile Status Page

According to the company, all 5.x and 6.x versions of ShareFile Storage Zone Controller contain a high-severity path traversal vulnerability.

The flaw allows an authenticated administrative user to:

  • Read arbitrary files accessible to the application’s service account.
  • Write attacker-controlled files into arbitrary directories.
  • Enumerate the server’s filesystem layout.

Although exploitation requires an authenticated administrator account, the potential impact remains significant.

Administrative credentials can be obtained through phishing campaigns, credential reuse, session hijacking, compromised VPN accounts, or other forms of initial access. Once an attacker gains administrative access, a vulnerability that permits unrestricted file access and arbitrary file writes can dramatically increase the chances of achieving full system compromise.

Reading arbitrary files may expose sensitive configuration data, encryption material, application secrets, or credentials stored on the server. Arbitrary file writes can potentially enable web shells, persistence mechanisms, or other malicious payloads, while filesystem enumeration gives attackers a complete map of the environment.

Individually these capabilities are dangerous. Combined, they provide attackers with a powerful post-authentication toolkit.

Security Updates Are Now Available

To address the issue, Progress has released the following patched versions:

  • ShareFile Storage Zone Controller 5.12.5
  • ShareFile Storage Zone Controller 6.0.2

Organizations are advised to install the appropriate update before restoring Storage Zone Controllers to production.

Interestingly, Progress says a CVE identifier has already been reserved, but it will not be published for approximately two weeks.

The company has not publicly explained why the CVE disclosure is being delayed despite patches already being available.

Was Anyone Actually Compromised?

At this stage, Progress says it has not identified any active threat and has found no indication of unauthorized access to customer accounts or data.

The company initially stated that it had received information from a credible external source regarding a potential threat targeting ShareFile deployments, prompting the emergency shutdown as a precaution while internal teams and external cybersecurity experts investigated the situation.

Whether attackers had already discovered the vulnerability, were actively probing systems, or simply possessed information suggesting exploitation was possible has not been disclosed.

Progress has also not revealed whether the vulnerability was discovered internally or responsibly reported by an external security researcher.

Another Reminder About Internet-Facing File Transfer Systems

The incident inevitably draws comparisons with the MOVEit Transfer attacks that unfolded in 2023.

In that campaign, the Clop ransomware operation exploited a zero-day vulnerability in Progress MOVEit Transfer to steal sensitive data from thousands of organizations worldwide before launching widespread extortion attempts.

While the newly disclosed ShareFile vulnerability is considerably different because it requires administrative authentication, both products share similar characteristics that continue to make enterprise file transfer solutions attractive targets.

These systems typically:

  • Store highly sensitive corporate documents.
  • Operate as internet-facing services.
  • Integrate with authentication systems and internal storage.
  • Are often treated as infrastructure components that receive infrequent maintenance.

That combination creates a high-value target for attackers searching for centralized repositories of sensitive information.

What Organizations Should Do

Organizations running ShareFile Storage Zone Controllers should verify which version is currently deployed and immediately update to version 5.12.5 or 6.0.2 before restoring services.

Administrators should also review authentication logs, administrator account activity, Windows event logs, and any unusual filesystem modifications performed before or during the shutdown period. Although Progress reports no evidence of customer compromise, verifying system integrity remains a prudent step for any exposed server.

As with many recent attacks against enterprise file transfer products, the lesson extends beyond a single vulnerability.

Any internet-facing platform responsible for storing or transferring sensitive business data should be considered a high-priority asset. Rapid patch deployment, continuous monitoring, strong administrative authentication, and minimizing unnecessary exposure remain among the most effective ways to reduce the risk posed by future zero-day vulnerabilities.

For security teams, this incident serves as another reminder that enterprise file sharing infrastructure continues to sit squarely in attackers’ crosshairs, making timely updates and proactive monitoring more important than ever.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading