ZeroHour
The Recordpublished ()ingested

CISA, experts warn of Citrix vulnerabilities being exploited by hackers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-24489
Unauthenticated RCE in Citrix ShareFile Storage Zones Controller (CVE-2023-24489)

CVE-2023-24489 is an improper access control flaw (CWE-284), rated critical at CVSS 9.8, in the customer-managed Citrix Content Collaboration ShareFile storage zones controller. It can be triggered remotely over the network by an unauthenticated attacker with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N). A successful attack allows the attacker to remotely compromise the customer-managed storage zones controller — described in vendor-adjacent coverage as remote code execution — giving control of the server that stores and syncs that organization's ShareFile files. Only organizations that self-host customer-managed storage zones controllers are affected; the vendor-managed (cloud) ShareFile service is not listed as affected. The flaw is being actively exploited in the wild: CISA added it to the KEV catalog on 2023-08-16, EPSS assigns a 97.3% probability of exploitation within 30 days (100th percentile), and the vendor urged customers to shut down or take unpatched controllers offline; ransomware use is not yet confirmed.

Do: Apply the fix specified in the Citrix/ShareFile security bulletin by upgrading every customer-managed storage zones controller to the vendor's patched release, and follow vendor guidance to shut down or take offline any controller that cannot be patched immediately. Check whether controllers are internet-exposed and hunt for signs of compromise (unexpected files, processes, or webshells on storage zones), since the flaw is in the KEV catalog and ransomware use has not been ruled out.

9.897% KEV
  • Citrix Content Collaboration (ShareFile) — customer-managed Storage Zones Controller (also listed by CISA as 'Citrix Content Co
moderate≈ thousands of internet-exposed customer-managed storage zone controllers (order-of-magnitude estimate)
CVE-2023-3519
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.

Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.

9.8100% KEV ransomware PoC
  • Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
  • Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
Full article975 words · extracted from therecord.media · click to collapse

Alarms have been raised about several vulnerabilities affecting products from Citrix that are being exploited widely by a variety of threat actors.

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency said a vulnerability affecting the Citrix Content Collaboration tool had been exploited and mandated that U.S. federal civilian agencies patch the issue by September 6.

Citrix released a warning about the bug — tracked as CVE-2023-24489 — on June 13, telling users that the issue affects the “customer-managed ShareFile storage zones controller.” ShareFile is a cloud-based file sharing and collaboration application for businesses that allows users to store files in their own data center.

If exploited, the vulnerability would allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

Citrix said the issue has a CVSS score of 9.1 out of 10 and urged customers to patch it as soon as possible. The company credited the vulnerability’s discovery to researchers at AssetNote, which published a proof-of-concept on July 4.

Security firm GreyNoise reported that it has observed hackers attempting to exploit the issue and said on Wednesday that after CISA’s notice they saw a steep spike in attacker activity around the bug.

“A search online shows roughly 1000-6000 instances are internet accessible. This popularity, combined with the software being used to store sensitive data, meant if we found anything it could have quite an impact,” AssetNote security researcher Dylan Pindur wrote.

“Given the number of instances online and the reliability of the exploit, we have already seen a big impact from this vulnerability.”

In a statement to Recorded Future News, ShareFile Senior Vice President David Le Strat said a fix for the vulnerability was released on May 11 and the company worked with customers to patch the issue. By June 13, at least 83% of customers had patched their instances, he said, noting that ShareFile also blocked all unpatched hosts from connecting to the software's cloud control plane — making them unusable with ShareFile.

While he acknowledged that there was a spike in attacks following the CISA notice, this “died down immediately given that the issue has been addressed.”

“When this vulnerability was discovered, we worked with and notified impacted customers in advance of the announced CVE to update to the latest version of our software to assure the safety of their data,” he said.

“Our control plane is no longer connected to any ShareFile StorageZones Controller (SZC) that is not patched. The incident affected less than 3% of our install base (2800 customers) There is no known data theft from this incident.”

Citrix Netscalers backdoored

Security companies have also raised alarms about CVE-2023-3519, a vulnerability affecting Citrix’s networking product NetScalers.

Researchers from cybersecurity firm Fox-IT said this week that they worked with the Dutch Institute of Vulnerability Disclosure to uncover a “large-scale exploitation campaign” involving the vulnerability.

“An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing webshells on vulnerable NetScalers to gain persistent access. The adversary can execute arbitrary commands with this webshell, even when a NetScaler is patched and/or rebooted,” they said in a blog post on Tuesday.

“At the time of writing, more than 1900 NetScalers remain backdoored. Using the data supplied by Fox-IT, the Dutch Institute of Vulnerability Disclosure has notified victims.”

The vulnerability was disclosed on July 18 alongside two other issues, and Fox-IT found more than 31,000 NetScalers vulnerable to the vulnerability. As of August 14, 1,828 NetScalers remain backdoored, the researchers said, noting that 1,248 are patched for the bug.

The researchers warned that even patched instances of NetScaler can still contain a backdoor, and they urged potential victims to examine their systems regardless of when the patch was applied.

“Most apparent from our scanning results is the percentage of patched NetScalers that still contain a backdoor. At the time of writing, approximately 69% of the NetScalers that contain a backdoor are not vulnerable anymore to CVE-2023-3519,” Fox-IT said.

“This indicates that while most administrators were aware of the vulnerability and have since patched their NetScalers to a non-vulnerable version, they have not been (properly) checked for signs of successful exploitation.”

The number of compromised, yet patched, instances indicates that the exploitation occurred before most administrators applied the patch. Fox-IT researchers said it is likely this specific exploitation campaign took place between late on July 20 and early on July 21.

Most victims observed by Fox-IT were in Germany, France, Switzerland and Japan — a curious targeting pattern considering Canada, Russia and the U.S. all had thousands of vulnerable NetScalers that day yet saw virtually no exploitation.

“As of now, we have no clear explanation for these differences, nor do we have a confident hypothesis to explain which NetScalers were targeted by the adversary and which ones were not. Moreover, we do not see a particular targeting in terms of victim industry,” they said.

“The monitoring and protection of edge devices such as NetScalers remains challenging. Sometimes, the window in which defenders must patch their systems is incredibly small. CVE-2023-3519 was exploited in targeted attacks before a patch was available and was later exploited on a large scale.”

Concern about the issue has grown so much that Google cybersecurity firm Mandiant worked with Citrix to create an Indicators of Compromise Scanner for the vulnerability.

Mandiant said they have observed “a threat actor consistent with a China-nexus based on known capabilities and history of targeting Citrix ADCs [Application Delivery Controllers]” exploiting the vulnerability.

Editor's note: Updated August 18 at 3 p.m. with more information from ShareFile.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warns-of-citrix-vulnerabilities