Cyber experts and officials raise alarms about exploits against Citrix and Apache products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-46604 | Unauthenticated RCE in Apache ActiveMQ via OpenWire Deserialization CVE-2023-46604 is a critical deserialization flaw (CWE-502) in the Java OpenWire protocol marshaller of Apache ActiveMQ that permits unauthenticated remote code execution (CVSS 9.8). An attacker with network access to either a Java-based OpenWire broker or client can manipulate serialized class types in the OpenWire protocol, causing the peer to instantiate arbitrary classes on the classpath and execute arbitrary shell commands. Successful exploitation yields full command execution on the target broker or client, with no authentication or user interaction required. Affected parties include anyone running ActiveMQ broker or Java client versions prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3, as well as NetApp E-Series products and Debian packages that ship affected ActiveMQ/OpenWire components. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-11-02 with known ransomware use (RansomHub), and has been used to drop Kinsing malware, Godzilla web shells, and the DripDropper implant, in some cases with attackers patching the flaw post-exploitation to lock out competing intruders. Do: Upgrade all ActiveMQ brokers and Java OpenWire clients to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 (or later), and apply the relevant NetApp E-Series and Debian updates for bundled components; restrict the OpenWire port (default TCP 61616) from untrusted networks. Hunt for indicators of the documented campaigns (Godzilla web shells, Kinsing malware, DripDropper, RansomHub) and verify the broker's current version, since attackers have been observed patching the flaw post-exploitation to hide from defenders. The CISA KEV listing means federal agencies must apply vendor mitigations or discontinue use of the product. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed OpenWire brokers (order of 10,000–100,000 by public scans), plus uncounted internal deployments and bundled NetApp/Debian… | |
| CVE-2023-4966 | Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation. Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts. | 7.5 | 100% | KEV ransomware |
| masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal… |
Full article614 words · extracted from therecord.media · click to collapse
Several new vulnerabilities with critical severity scores are causing alarm among experts and cyber officials. Zero-day bugs affecting products from Citrix and Apache have recently been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) known exploited vulnerability (KEV) list. Incident responders at the cybersecurity company Rapid7 warned of hackers connected to the HelloKitty ransomware exploiting a vulnerability affecting Apache ActiveMQ, classified as CVE-2023-46604. Apache ActiveMQ is a Java-language open source message broker that facilitates communication between servers. The incident responders said they have dealt with two situations in which HelloKitty ransomware was used after exploitation of the bug. The proof of concept exploit code is available and resembles what they saw in the two incidents they responded to, Rapid7 said. CISA added the vulnerability to its catalog of known exploited bugs on Thursday evening, giving federal civilian agencies until November 23 to address the issue. The agency did not confirm if ransomware actors were exploiting the bug. Apache disclosed the vulnerability and released new versions of ActiveMQ on October 25. Experts from Huntress confirmed that they too have seen hackers exploit the vulnerability and attempt to deploy the HelloKitty ransomware. The vulnerability carries the highest CVSS severity score of 10 out of 10. “Exploitation for this attack is trivial,” they said, adding that the module used in attacks “works like a charm against vulnerable instances of ActiveMQ.” A vulnerability dubbed ‘Citrix Bleed’ is being exploited in attacks on government organizations as well as companies in the professional services and technology industries. The vulnerability allows hackers to gain access to sensitive information, according to a security bulletin from Citrix. On October 10, Citrix said the bug — CVE-2023-4966 — impacts NetScaler ADC and NetScaler Gateway appliances. Researchers from the cybersecurity company AssetNote have since released a proof-of-concept (PoC) exploit. The bug was rated a 9.4 out of 10 on the CVSS severity scale. Mandiant has identified zero-day exploitation of this vulnerability in the wild beginning in late August. The Google-owned cybersecurity giant is currently investigating multiple instances of successful exploitation that allowed hackers to take over NetScaler ADC and Gateway appliances. “The Netscaler exploitation is at large scale right now,” said Timothy Morris, a security adviser at the cyber firm Tanium. CISA added the bug to its catalog of exploited bugs last month, giving federal civilian agencies until November 8 to patch the issue. But several cybersecurity experts warned that it was not enough to simply patch the vulnerability. Those using the products need to investigate signs of compromise. Hoxhunt CEO Mika Aalto told Recorded Future News that it is likely there are many organizations who use the affected products and haven’t performed the recommended mitigations. The research tool ShadowServer shows that thousands of instances where the tool is used are still vulnerable to the issue as of November 2, with nearly 2,000 in North America alone. Cybersecurity expert Kevin Beaumont said at least two ransomware gangs are now attempting to exploit the vulnerability in attacks, while Mandiant found four different groups attempting exploitation. Beaumont called for government cyber agencies to “start banging loud drums about getting orgs to patch #CitrixBleed” on the social media site Mastodon. “People are going wild with it — it’s point and click simple access to Remote Desktop inside orgs firewalls without generating any alerts or logs,” he wrote.Mandiant warns of ‘Citrix Bleed’
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cyber-officials-raise-alarms-citrix-apache