News: 1698181211

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Citrix urges 'immediate; patch for critical NetScaler bug as exploit POC made public

(2023/10/24)


Citrix has urged admins to "immediately" apply a fix for CVE-2023-4966, a critical information disclosure bug that affects NetScaler ADC and NetScaler Gateway, admitting it has been exploited.

Plus, there's a proof-of-concept exploit, dubbed [1]Citrix Bleed , now on GitHub. So if you are using an affected build, at this point assume you've been compromised, apply the update, and then kill all active sessions per Citrix's advice from Monday.

The company's first [2]issued a patch for compromised devices on October 10, and last week Mandiant warned that criminals — most likely cyberspies — have been [3]abusing this hole to hijack authentication sessions and steal corporate info since at least late August.

[4]

Six days after the Google-owned threat intel firm sounded the alarm, Citrix weighed in.

[5]

[6]

"If you are using affected builds and have configured NetScaler ADC as a gateway (VPN virtual server, ICA proxy, CVPN, RDP proxy) or as an AAA virtual server, we strongly recommend that you immediately [7]install the recommended builds ," the vendor [8]said in a Cloud Software Group blog post about CVE-2023-4966 published on Monday.

"We now have reports of incidents consistent with session hijacking, and have received credible reports of targeted attacks exploiting this vulnerability," Citrix added.

[9]

Oddly, Citrix didn't release any additional details about these [10]targeted attacks , which Mandiant last week said were used to hit tech firms, government organizations, and professional services companies.

[11]Critical Citrix bug exploited by data thieves weeks before being patched

[12]It's 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

[13]Cisco fixes critical IOS XE bug but malware crew way ahead of them

[14]1Password confirms attacker tried to pull list of admin users after Okta intrusion

A Citrix spokesperson declined to comment on how many organizations have been compromised, and who or what the criminals are targeting in the attacks.

"The security bulletin and blog are the extent of our external statements at this time," the Citrix spokesperson told The Register .

Also last week, Mandiant Consulting CTO Charles Carmakal [15]warned that "organizations need to do more than just apply the patch — they should also terminate all active sessions. These authenticated sessions will persist after the update to mitigate CVE-2023-4966 has been deployed."

Citrix, in the Monday blog, also echoed this mitigation advice and told customers to kill all active and persistent sessions using the following commands:

[16]

kill icaconnection -all

kill rdp connection -all

kill pcoipConnection -all

kill aaa session -all

clear lb persistentSessions

The US Cybersecurity and Infrastructure Security Agency (CISA) last Wednesday [17]added CVE-2023-4966 to its Known Exploited and Vulnerabilities Catalog, and classified the bug as "unknown" in the "used in ransomware campaigns" column. The addition means federal agencies, and those that do business with them, should have this one fixed sharpish.

While the attacks to date are more likely linked to snooping campaigns, "we anticipate other threat actors with financial motivations will exploit this over time," Carmakal said previously. But let's face it, they usually do. ®

Get our [18]Tech Resources



[1] https://github.com/assetnote/exploits/tree/main/citrix/CVE-2023-4966

[2] https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/

[3] https://www.theregister.com/2023/10/18/critical_citrix_bug_exploited/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTg@hSFXQIyN6ddsdGtfJAAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTg@hSFXQIyN6ddsdGtfJAAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTg@hSFXQIyN6ddsdGtfJAAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967

[8] https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTg@hSFXQIyN6ddsdGtfJAAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/10/18/critical_citrix_bug_exploited/

[11] https://www.theregister.com/2023/10/18/critical_citrix_bug_exploited/

[12] https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/

[13] https://www.theregister.com/2023/10/23/cisco_iosxe_fix/

[14] https://www.theregister.com/2023/10/24/1password_confirms_all_logins_are/

[15] https://www.linkedin.com/feed/update/urn:li:activity:7120179274774417408/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTg@hSFXQIyN6ddsdGtfJAAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

[18] https://whitepapers.theregister.com/



wondering if these exploits work...

Nate Amsden

..against Citrix VPN systems that have no users connected? Seems like exploitation requires at least one user session to be active. I disabled my main access gateway("disable vpn vserver ") a few months ago(following the last exploit), I did used to use access gateway, and plan to get back to using it again, but upgrading from Netscaler 12.1 -> 13.0 broke duo authentication and I haven't gotten round to fixing it yet, so was sitting without anyone connected to it for a few months (I was the only one that used it, everyone else uses another VPN which I am now using as well, though liked Citrix more)

Netscalers by default I believe come with a 5 user license, so wouldn't surprise me if there are a lot of systems out there that may have VPN configured just don't get much usage, in my case I kept it alive over the years primarily as a backup VPN for other IT staff if there was an issue with the primary system (which uses a completely different vendor/product), didn't cost anything since we needed the load balancers for load balancing anyway. I still patched anyway, even though likely the exploits would be completely ineffective as my only vpn vservers were disabled.

"I assure you the thought never even crossed my mind, lord."
"Indeed? Then if I were you I'd sue my face for slander."
-- Terry Pratchett, "The Colour of Magic"