October 3, 2023

Researchers have spotted the exploitation of a recent critical remote code execution (RCE) vulnerability in Citrix Sharefile, a cloud based file sharing and collaboration solution.

Tracked as CVE-2023-24489 with a CVSS score of 9.1 was the result of errors leading to unauthenticated file upload, which could then be exploited to obtain Remote Code Execution.

An internet scan has resulted in the findings that about 6000 ShareFile instances are accessible publicly , potentially making it a popular target for attackers, given that it might store sensitive data which will be considered as a biggest impact.


Citrix patched the flaw in June 2023 with the release of ShareFile storage zones controller version 5.11.24, warning that it could lead to full application compromise.

Earlier this month, a working proof-of-concept (PoC) code targeting the vulnerability and additional PoC exploits have since been released by researchers from Assetnote, increasing the likelihood of in-the-wild exploitation.

Now, another firm, Graynoise, has created a tag for CVE-2023-24489 to track in-the-wild exploitation, and the first exploit attempts were logged.

Citrix ShareFile customers using storage zones controllers are advised to update their installations as soon as possible.

Leave a Reply

%d bloggers like this: