Citrix NetScaler zero-day exploited in the wild, patch is available (CVE-2023-3519)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-27510 | Unauthorized access to Gateway user capabilities Unauthorized access to Gateway user capabilities NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2022-27518 | Unauthenticated RCE/Authentication Bypass in Citrix ADC and Gateway CVE-2022-27518 is a critical flaw in Citrix Application Delivery Controller (ADC) and Gateway firmware that permits unauthenticated remote arbitrary code execution, which CISA characterizes as an authentication bypass. It is triggered remotely over the network with no credentials, privileges, or user interaction required (CVSS 3.1: AV:N/AC:L/PR:N/UI:N, score 9.8), so any affected appliance with an internet-reachable interface is a potential target. A successful attacker gains code execution on the appliance and access to sensitive resources, which is especially dangerous on VPN gateway and load-balancing deployments that front-door enterprise networks. All organizations running Citrix ADC or Gateway appliances are potentially affected, with internet-exposed devices at greatest risk. The flaw is being actively exploited in the wild, including by state-sponsored actors; it was added to CISA KEV on 2022-12-13 and Citrix and the NSA publicly urged admins to patch, though no public proof-of-concept is known. Do: Apply the fixed firmware updates per Citrix's vendor instructions immediately, prioritizing internet-facing ADC and Gateway appliances, since the flaw is in CISA KEV and actively exploited by state-sponsored actors. Until patched, restrict or shield appliance interfaces where feasible, and review internet-exposed devices for indicators of compromise given the absence of a public PoC. | 9.8 | 7% | KEV |
| largetens of thousands of internet-exposed ADC/Gateway appliances, with thousands reported still unpatched after disclosure | |
| CVE-2023-3467 +1 in the same advisory: …3466 | Privilege Escalation to root administrator (nsroot) Privilege Escalation to root administrator (nsroot) NVD description · AI analysis pending | 8.0 group max | 1% |
| — | ||
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… |
Full article455 words · extracted from helpnetsecurity.com · click to collapse
Citrix has patched three vulnerabilities (CVE-2023-3519, CVE-2023-3466, CVE-2023-3467) in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), one of which is a zero-day being exploited by attackers.
A zero-day patched (CVE-2023-3519)
CVE-2023-3519 is a remote code execution (RCE) vulnerability that could allow an unauthenticated threat actor to execute arbitrary code on a vulnerable server. At this time there is no public PoC, but the vulnerability has been observed being exploited in the wild.
Citrix has noted that the appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server to be vulnerable.
CVE-2023-3466 is a reflected XXS vulnerability that can be exploited if the victim accesses an attacker-controlled link in the browser while being on a network with connectivity to the NSIP.
CVE-2023-3467 could allow a threat actor to elevate privileges to root administrator (nsroot). Authenticated access to NSIP or SNIP with management interface access is required to leverage this vulnerability.
The vulnerabilities have been reported to the company by Wouter Rijkbost and Jören Guerts of Resillion.
Remediation
Citrix appliances have been a popular target for cybercriminals.
In early 2022, the company reported the exploitation of a RCE vulnerability (CVE-2022-27518) in its Citrix ADC deployments by a Chinese state-sponsored group. Earlier this year, ransomware threat actors also exploited an auth bypass flaw (CVE-2022-27510) on Citrix ADC and Gateway.
The company noted that the following supported versions of NetScaler ADC and NetScaler Gateway are affected by the three patched vulnerabilities:
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13
- NetScaler ADC and NetScaler Gateway 13.0 before 13.0-91.13
- NetScaler ADC 13.1-FIPS before 13.1-37.159
- NetScaler ADC 12.1-FIPS before 12.1-55.297
- NetScaler ADC 12.1-NDcPP before 12.1-55.297
Fixes have been provided for all these versions including the later releases.
NetScaler ADC and NetScaler Gateway version 12.1 have reached end-of-life, meaning they are now vulnerable and should be updated to a supported version as soon as possible.
“This bulletin only applies to customer-managed NetScaler ADC and NetScaler Gateway. Customers using Citrix-managed cloud services or Citrix-managed Adaptive Authentication do not need to take any action,” Citrix added.
There is a document containing indicators of compromise and “mentioning a PHP webshell, a SetUID binary and an IP” that enterprise admins can use to check whether their Citrix systems have been compromised, but it has yet to be made publicly available.
UPDATE (July 19, 2023, 12:20 p.m. ET):
An unofficial guide for investigating whether your Citrix Netscaler installations have been compromised via CVE-2023-3519 has been made public.
UPDATE (July 21, 2023, 07:15 a.m. ET):
The exploitation of the Citrix NetScaler ADC zero-day vulnerability (CVE-2023-3519) was first spotted by a critical infrastructure organization, who reported it to the Cybersecurity and Infrastructure Security Agency (CISA).
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/07/19/cve-2023-3519/