HomeSecurityHackers target Citrix servers for remote code execution vulnerability

Hackers target Citrix servers for remote code execution vulnerability

Hackers perform scans to find Citrix servers vulnerable to a critical security flaw in ADC and Gateway products, researchers warned.

Published in December, the serious vulnerability, referred to as CVE-2019-19781, affects the Citrix Application Delivery Controller (ADC) – also known as NetScaler ADC – together with the Citrix Gateway, formerly known as NetScaler Gateway. Initially reported by Mikhail Klyuchnikov from Positive Technologies, the critical vulnerability allows directory traversal and, if exploited, enables threat actors to conduct remote code execution (RCE) attacks.

Hackers target Citrix servers for remote code execution vulnerability

According to Citrix's security advisory, these products are affected:

  • Citrix ADC and Citrix Gateway version 13.0 all supported builds
  • Citrix ADC and NetScaler Gateway version 12.1 all supported builds
  • Citrix ADC and NetScaler Gateway version 12.0 all supported builds
  • Citrix ADC and NetScaler Gateway version 11.1 all supported builds
  • Citrix NetScaler ADC and NetScaler Gateway version 10.5 all supported builds

The researchers estimate that at least 80,000 organizations in 158 countries are ADC users and could therefore be at risk. The companies at risk are based primarily in the US – around 38% – as well as the UK, Germany, the Netherlands and Australia.

“Depending on the specific parameters, Citrix applications can be used to connect to workstations and critical business systems (including ERP),” says Positive Technologies. “In almost all cases, Citrix applications are accessible at the perimeter of the company’s network and are therefore the first to be attacked. This vulnerability allows any unauthorized attacker not only to access published applications, but also to attack other resources on the Citrix server’s internal network.”

As reported by Bleeping Computer, researchers in the field of cybersecurity have identified a spike in scans for Citrix servers that are possibly vulnerable to the bug.

There doesn’t appear to be any publicly available exploit code in widespread use — at least, not yet. The research’s dean, Johannes Ullrich of the SANS Institute of Technology, noted in his own reviews that the current scans don’t appear to be “sophisticated” in any way — some of which go no further than GET requests — but added that “other sources that I consider reliable have stated that they were able to create a code execution exploit.”

A patch issue , but Citrix has in the meantime published guidelines for handling the situation. The company recommends that IT admins run a set of commands, accessible here, to adjust response policies.

"Citrix strongly encourages customers to implement the provided workaround immediately. Customers should then upgrade all of their vulnerable devices to a stable version of the device firmware when it is released," it says

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS