ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical Citrix NetScaler bug fixed, upgrade ASAP! (CVE-2025-5777)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-4966
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.

Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.

7.5100% KEV ransomware
  • Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
CVE-2025-5349
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

NVD description · AI analysis pending
8.75%
  • citrix netscaler application delivery controller
  • citrix netscaler gateway
CVE-2025-5777
Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned.

Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw.

9.3100% KEV ransomware
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of…
CVE-2025-6543
Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild

Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known.

Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading.

9.210% KEV
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable)
Full article490 words · extracted from helpnetsecurity.com · click to collapse

Citrix has fixed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway reminiscent of the infamous and widely exploited CitrixBleed flaw.

The vulnerabilities have been privately disclosed and there is no indication that they are under active exploitation. Nevertheless, the company has urged to install the relevant updated versions as soon as possible and terminate active sessions.

About the vulnerabilities (CVE-2025-5777, CVE-2023-4966)

CVE-2025-5777 is an out-of-bounds read flaw stemming from insufficient input validation. Like CitrixBleed (CVE-2023-4966), it may allow unauthorized attackers to grab valid session tokens from the memory of internet-facing Netscaler devices by sending malformed request. The session tokens can then be used to gain access to the appliances.

The vulnerability is exploitable over the network without any privileges or user interaction, but only on NetScaler devices that have been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or Authentication, Authorization, and Accounting server.

CVE-2025-5349, which stems from improper access control on the NetScaler Management Interface, has also been fixed, but this one can be exploited only by attackers that have access to the device’s NetScaler-owned IP addresses or its cluster management IP address (if it’s a clustered appliance).

The vulnerabilities affect the following customer-managed appliances:

  • NetScaler ADC and NetScaler Gateway 14.1 prior to v14.1-43.56
  • NetScaler ADC and NetScaler Gateway 13.1 prior to v13.1-58.32
  • NetScaler ADC 13.1-FIPS and NDcPP prior to v13.1-37.235-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS prior to v12.1-55.328-FIPS

“Secure Private Access on-prem or Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities. Customers need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerabilities,” the company noted.

The company also advised customers to kill terminate active active ICA and PCoIP sessions after they’ve upgraded their NetScaler appliances, so that potentially stolen session tokens are voided.

“Rebooting appliances instead of [terminating these sessions] isn’t recommended,” Anil Shetty, senior VP of Engineering at NetScaler pointed out. In case of cluster deployments, the kill sessions commands should be executed on each of the nodes, and in case of high-availability pairs, executing the commands on the Primary active node is sufficient, he added.

Customers with NetScaler ADC and NetScaler Gateway end-of-life versions 12.1 and 13.0 are advised to upgrade their appliances to one of the supported (and fixed) versions.

Threat actors have historically been quick to leverage vulnerabilities in Citrix NetScaler ADC, so speed is of the essence here.

UPDATE (June 25, 2025, 02:10 p.m. ET):

Citrix has issued emergency patches for a NetScaler ADC and NetScaler Gateway vulnerability (CVE-2025-6543) that is being leveraged by attackers.

CVE-2025-6543 is a memory overflow vulnerability that leads to “unintended control flow and Denial of Service.”

“Exploits of CVE-2025-6543 on unmitigated appliances have been observed,” the company said, but did not specify what the attackers are using it for.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/06/23/critical-citrix-netscaler-bug-fixed-upgrade-asap-cve-2025-5777/