EXPOSURES › CVE-2021-22941
CVE-2021-22941
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCitrix ShareFile allowed unauthenticated attackers to remotely compromise storage zones controllers, actively exploited and linked to ransomware activity.
An improper access control vulnerability in Citrix ShareFile enabled unauthorized remote compromise of storage zones controllers, which was actively exploited in the wild and associated with ransomware campaigns. DIB organizations using ShareFile face significant exposure and potential compliance failures (NIST 800-171 controls 3.a, 3.b, 4.a) and should immediately patch and review access controls.
Shame score — The vulnerability allowed unauthenticated remote code execution and was actively exploited, demonstrating a significant failure in access control implementation and a preventable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |