QID 375871

Date Published: 2021-09-21

QID 375871: Citrix ShareFile Storage Zone Unauthenticated Remote Code Execution (RCE) Vulnerability (CTX328123)

Citrix ShareFile is a secure file sharing and transfer service.

A security issue has been identified in Citrix ShareFile storage zones controller which, if exploited, would allow an unauthenticated attacker to remotely compromise the storage zones controller.

Affected Versions:
Citrix ShareFile storage zones controller prior to 5.11.20

NOTE : Customers using Citrix-managed storage zones in the cloud are not affected by this issue.

QID Detection Logic (Authenticated):
This QID detects vulnerable versions by fetching bin\StorageCenter.dll file versions from the HKLM\SOFTWARE\Citrix\StorageCenter\InstallDir registry

Successful exploitation of this vulnerability allows full system compromise

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to CTX328123 for further details pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 375871

    Software Advisories
    Advisory ID Software Component Link
    CTX328123 URL Logo support.citrix.com/article/CTX328123