Skip to content
Rush Commerce
Field Notes3 min read

ShareFile zero-day: your vendor told you to unplug

Progress ordered ShareFile customers to power off Storage Zone Controllers, then confirmed a path traversal zero-day. Patches shipped before the CVE did. Here's the lesson.

Progress told ShareFile customers to shut down their Storage Zone Controllers over a "credible external security threat," disabled the affected accounts, and only confirmed the underlying zero-day days later. The patch shipped before the CVE was even published. If your file-sharing runs on ShareFile, this is a patch-now item — and if it doesn't, it's still the cleanest recent example of a failure mode most small businesses have never planned for.

What actually happened

Progress confirmed a high-severity path traversal flaw affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, and shipped fixed builds 5.12.5 and 6.0.2. Per BleepingComputer, an authenticated administrative user could read arbitrary files reachable by the application's service account, write attacker-controlled content into arbitrary directories, or enumerate the server filesystem. Progress says it has no indication of unauthorized access to any customer account or data.

The sequence is the interesting part. Help Net Security reported the emergency shutdown instruction on July 13; the vulnerability confirmation and patches followed. Progress reserved a CVE but held publication for roughly two weeks — deliberately, to give customers a head start before the details are public.

Storage Zone Controllers are the customer-managed Windows servers that keep your files on-prem while the ShareFile cloud handles the front end. Which means the box holding your documents is the box you patch.

Why an emergency shutdown matters for your business

Nobody's runbook says "power off the file server today, indefinitely, and we'll tell you why later." But that was the instruction, and it was the right one. The question is whether your business could have followed it.

Three things to know before it's you. One: which vendors can hand you an outage you didn't choose — and how do they reach you? A support-portal banner nobody reads is not a notification channel. Two: what breaks if a given system goes dark for 48 hours, and what's the manual path? Three: who applies the patch on a self-managed box on a Saturday, and how fast?

Also note what this episode does to CVE-driven security. Progress patched before publishing. If your process starts when a CVE lands in a feed, you were days behind on this one. Vendor advisories are the leading indicator; the CVE is the receipt.

Key takeaways

  • Progress told ShareFile customers to power off Storage Zone Controllers on July 13 over a credible threat, then confirmed a path traversal zero-day in all 5.x and 6.x versions
  • Fixed builds are 5.12.5 and 6.0.2 — patch and restore, don't wait for the CVE, which Progress deliberately delayed
  • Progress reports no evidence of unauthorized access to customer accounts or data
  • Self-managed appliances mean vendor-initiated downtime is your operational problem: know the notification path, the blast radius, and who patches on a weekend

Not sure what goes dark if a vendor says "unplug it"? We map the systems your business actually depends on and build the fallbacks. See what we build.

Sources: BleepingComputer, Help Net Security.

  • #sharefile
  • #zero-day
  • #patch-management
  • #vendor-risk
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.