CVE-2021-22941

CRITICAL(9.8)KEVRansomwareLikely Exploited

Citrix ShareFile Improper Access Control Vulnerability

Description

CVE-2021-22941 is an improper access control vulnerability in Citrix ShareFile Storage Zones Controller that allows an unauthenticated attacker to upload arbitrary files to the server. The flaw exists in the document processing functionality, where insufficient authorization checks enable an attacker to upload malicious files that can then be executed to achieve remote code execution. With an EPSS score of 83.3% (99.3rd percentile), this vulnerability has been heavily targeted. CISA has added CVE-2021-22941 to the Known Exploited Vulnerabilities catalog.

KEV Information

Vendor
Citrix
Product
ShareFile
Date Added
March 25, 2022
Due Date
April 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
citrixsharefile storagezones controller< 5.11.20

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-284: Improper Access Control

CVE-2021-22941 is caused by improper access control in Citrix ShareFile Storage Zones Controller. The application fails to properly enforce authentication and authorization requirements for file upload operations, allowing an unauthenticated attacker to upload arbitrary files including executable content to the server.

Learn more: CWE-284 — Improper Access Control

Impact Analysis

CVE-2021-22941 has a CVSS v3.1 base score of 9.8 (Critical), reflecting the severe consequences of unauthenticated arbitrary file upload. The vulnerability requires no authentication, no user interaction, and can be exploited remotely with low complexity. Successful exploitation allows an attacker to upload and execute malicious files on the ShareFile Storage Zones Controller, leading to complete server compromise. The EPSS score of 83.3% (99.3rd percentile) indicates heavy exploitation activity. Citrix ShareFile is widely used for enterprise file sharing and collaboration, making compromised instances particularly valuable for accessing sensitive corporate data.

Exploit Maturity

CVE-2021-22941 has been actively exploited with public exploit code available for this vulnerability. CISA confirmed exploitation by adding it to the KEV catalog. The vulnerability has been targeted by threat actors seeking access to enterprise file sharing infrastructure and the sensitive data it contains. The EPSS score of 83.3% (99.3rd percentile) reflects the extensive exploitation activity observed against exposed ShareFile instances.

Remediation

  1. Apply the Citrix security update for ShareFile Storage Zones Controller that addresses CVE-2021-22941 immediately. Follow Citrix's security bulletin for specific patching instructions.
  2. Restrict network access to the ShareFile Storage Zones Controller, ensuring it is not directly accessible from the internet without authentication.
  3. Audit ShareFile Storage Zones Controllers for signs of compromise including uploaded web shells, modified configurations, unauthorized user accounts, and suspicious file activity.
  4. Review and strengthen access controls for the ShareFile environment, implementing multi-factor authentication and monitoring all administrative actions.
  5. Implement a web application firewall (WAF) in front of ShareFile deployments to filter malicious upload requests and provide an additional layer of protection.

Technical Details

CVE-2021-22941 is an improper access control vulnerability (CWE-284) in Citrix ShareFile Storage Zones Controller. The vulnerability exists in the file upload functionality of the Storage Zones Controller, which handles document storage and retrieval for the ShareFile cloud storage service. Due to insufficient authorization checks in certain upload endpoints, an unauthenticated attacker can bypass access controls and upload arbitrary files to the server. By uploading a web shell or other executable content, the attacker can then execute commands on the underlying server with the privileges of the ShareFile application. The Storage Zones Controller typically has access to all stored files and enterprise data flowing through the ShareFile platform, maximizing the impact of a successful compromise.

Frequently Asked Questions

Is CVE-2021-22941 being actively exploited?

Yes, CVE-2021-22941 has been actively exploited with public exploit code available. CISA confirmed exploitation by including it in the KEV catalog. The EPSS score of 83.3% indicates heavy exploitation targeting ShareFile deployments.

What products are affected by CVE-2021-22941?

Citrix ShareFile Storage Zones Controller is affected. The vulnerability allows unauthenticated file upload that can lead to remote code execution on the storage controller server.

How do I fix CVE-2021-22941?

Apply Citrix's security update for ShareFile Storage Zones Controller immediately. Restrict network access to the controller and audit for signs of compromise including unauthorized files and web shells.

How severe is CVE-2021-22941?

CVE-2021-22941 has a CVSS v3.1 score of 9.8 (Critical) and enables unauthenticated remote file upload leading to code execution. The EPSS score of 83.3% confirms heavy exploitation activity targeting enterprise file sharing infrastructure.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score53.59%
EPSS Percentile98.9%

Dates

PublishedSeptember 23, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.