Zero‑Day Path Traversal in Progress ShareFile Storage Zone Controllers Forces Emergency Shutdown
What Happened — Progress Software disclosed a high‑severity zero‑day path‑traversal flaw in all 5.x and 6.x versions of its ShareFile Storage Zone Controller (SZC). The vulnerability allows an authenticated admin to read arbitrary files, write attacker‑controlled content, and enumerate the server’s filesystem. Progress shut down SZC instances, issued emergency patches (5.12.5, 6.0.2) and reserved a CVE, reporting no evidence of a breach.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous configuration and patch‑management controls (SOC 2 CC6.1) and auditable evidence that updates are applied promptly.
- Highlights the importance of maintaining a defensible change‑control trail for on‑premises components that integrate with cloud services.
- Aligns with the Control Mapping capability, which helps organizations map such vulnerability‑remediation actions to SOC 2 criteria and collect real‑time proof for auditors.
Who Is Affected – Primarily enterprises using ShareFile’s on‑premises Storage Zone Controllers – a common component in technology‑SaaS, professional services, and regulated industries that require hybrid cloud file storage.
Recommended Actions
- Inventory all ShareFile SZC instances and verify they run a vulnerable 5.x/6.x version.
- Apply the released patches (5.12.5 or 6.0.2) immediately and document the change in your configuration‑management system.
- Update your SOC 2 control evidence repository to include patch‑deployment logs, vulnerability‑assessment reports, and post‑patch validation results.
- Review and tighten admin‑account provisioning to enforce least‑privilege and MFA, reducing the impact of any future authenticated exploits.
Source: BleepingComputer
Technical Notes – The flaw is a path‑traversal (CWE‑22) that requires an authenticated administrative account. It enables read/write of arbitrary files and full filesystem enumeration. A CVE identifier is pending publication. No public exploitation has been observed. Source: same as above