CISA adds Chrome and Citrix NetScaler to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6548 +1 in the same advisory: …6549 | Authenticated Code-Injection RCE in Citrix NetScaler ADC/Gateway CVE-2023-6548 is a code injection flaw (CWE-94) in the management interface of Citrix NetScaler ADC and NetScaler Gateway that allows remote code execution. It is triggered when an attacker who can reach the appliance's NSIP, CLIP, or a SNIP with management interface access authenticates with valid low-privileged credentials and sends crafted input that the appliance turns into executable code. Successful exploitation yields authenticated remote code execution in the context of the management interface, with high impact on the confidentiality, integrity, and availability of the appliance. Affected organizations are those running Citrix NetScaler ADC or NetScaler Gateway appliances, particularly deployments whose management interfaces are reachable from less-trusted networks or shared with low-privileged users. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17 and urged immediate action, though no public proof-of-concept code is known and EPSS currently estimates a ~3.2% chance of exploitation within 30 days. Do: Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the fixed builds in Citrix's security bulletin for CVE-2023-6548 (released alongside the companion CVE-2023-6546 NetScaler privilege-escalation fix), per CISA's KEV directive to apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Reduce exposure by restricting management interface access on the NSIP, CLIP, and SNIPs to trusted admin networks and by removing or constraining low-privileged accounts that do not need management access. Review appliance authentication logs and configurations for unexpected logins or changes, since exploitation requires authenticated access to the management interface. | 8.8 group max | 3% | KEV |
| large~tens of thousands of NetScaler appliances with reachable management interfaces (out of a very large global installed base) | |
| CVE-2024-0519 | Out-of-Bounds Memory Access in Google Chrome/Chromium V8 (Actively Exploited) Google Chrome's V8 JavaScript engine, in versions prior to 120.0.6099.224, contains an out-of-bounds memory access flaw (CWE-787 out-of-bounds write / CWE-125 out-of-bounds read) that is triggered when a user visits a specially crafted HTML page. A remote attacker who lures a victim to such a page can potentially corrupt the heap and execute code in the context of the browser. Successful exploitation could lead to exposure of sensitive information, data tampering, or denial of service (CVSS 3.1: 8.8 High; user interaction is required). Anyone running a vulnerable Chrome/Chromium build is affected, including downstream products that embed V8, such as Fedora's Chromium/Chrome packages and Couchbase Server. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-17, and news coverage describes it as one of Google's actively exploited Chrome zero-days patched in January 2024. Do: Update Google Chrome to 120.0.6099.224 or later (and restart the browser so the new version is fully loaded); verify fleet versions via Chrome's version reporting if managing enterprise deployments. Fedora users should install the updated chromium/chrome packages via the distribution's update channel, and Couchbase Server operators should apply the vendor's guidance. Because the flaw is on CISA's KEV catalog, federal and other regulated environments are required to apply vendor mitigations promptly; the only effective mitigation is patching, as no public PoC or alternate workaround is documented. | 8.8 | 4% | KEV |
| massbillions of users (Chrome holds roughly 65% of desktop browser share with over 3 billion users, and any browser prior to 120.0.6099.224 was vulnerable) |
Full article525 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Chrome and Citrix flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
- CVE-2023-6548 – Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability.
- CVE-2023-6549 – Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability.
- CVE-2024-0519 – Google Chromium V8 Out-of-Bounds Memory Access Vulnerability.
This week Citrix warned customers to install security updates to address two actively exploited zero-day vulnerabilities, tracked as CVE-2023-6548 and CVE-2023-6549, impacting Netscaler ADC and Gateway appliances.
“Exploits of these CVEs on unmitigated appliances have been observed. Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.” reads the advisory.
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
An attacker can trigger the flaw to gain remote code execution or cause a denial-of-service condition.
The vulnerability CVE-2023-6548 is an authenticated (low privileged) remote code execution affecting Management Interface. In order to exploit this issue, an attacker must have access to NSIP, CLIP or SNIP with management interface access.
The company pointed out that CVE- 2023- 6548 only impacts the management interface. Cloud Software Group strongly recommends that network traffic to the appliance’s management interface is separated, either physically or logically, from normal network traffic. The vendor recommends that customers do not expose the management interface to the internet, as explained in the secure deployment guide.
The vulnerability CVE-2023-6549 is a Denial of Service. To be exploited the appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
This week, Google released security updates to address the first Chrome zero-day vulnerability of the year that is actively being exploited in the wild.
The high-serverity vulnerability, tracked as CVE-2024-0519, is an out of bounds memory access in the Chrome JavaScript engine. The flaw was reported by Anonymous on January 11, 2024.
“The Stable channel has been updated to 120.0.6099.234 for Mac and 120.0.6099.224 for Linux and 120.0.6099.224/225 to Windows which will roll out over the coming days/weeks.” reads the security advisory published by the IT giant. “Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.”
A remote attacker can exploit the flaw by tricking a user into visiting a crafted HTML page to potentially exploit heap corruption.
As usual, Google did not share details of the attacks that exploited the CVE-2024-0519 zero-day in the wild.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by February 2, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/157717/hacking/chrome-citrix-bugs-known-exploited-vulnerabilities-catalog.html