HomeSecurityRecently fixed Citrix NetScaler bug was used as a zero-day

Recently fixed Citrix NetScaler bug was used as a zero-day

A critical vulnerability, known as CVE-2023-4966, found in Citrix NetScaler ADC/Gateway appliances, appears to have been used as a zero-day since late August.

Citrix NetScaler zero-day

The vulnerability was patched last week. It allows attackers to access secrets on devices configured as authentication ,authorization, and accounting (AAA) virtual servers.

Citrix published a security on October 10, which contained few technical details. It recommended installing the latest update immediately.

See also: Signal: No evidence of zero-day vulnerability

A recent report from Mandiant revealed that signs of exploitation of the Citrix NetScaler vulnerability, CVE-2023-4966, have been detected since August, for theft and account theft.

“Mandiant has identified a zero-day exploitation of this vulnerability, as of late August 2023,” the cybersecurity company says.

According to the company, successful exploitation could lead to the compromise of existing authenticated sessions, bypassing multi-factor authentication or other strong authentication requirements.

The company warns that compromised sessions remain even after the security. Depending on the privileges of the compromised account, attackers can leverage the method to move laterally or compromise more accounts.

Security researchers observed that hackers used CVE-2023-4966 to access infrastructure belonging to government organizations and technology companies.

See also: Apple: Fixes iOS Kernel zero-day on older iPhone models

Recently fixed Citrix NetScaler bug was used as a zero-day

Citrix NetScaler: Zero-day vulnerability fixed

In addition to implementing the Citrix update, Mandiant also recommended some other protection measures for NetScaler ADC/Gateway administrators:

  • Restrict ingress IP addresses if immediate application of the update is not possible.
  • Terminate all post-upgrade sessions and run the CLI command: clear lb persistentSessions<vServer> .
  • Rotate credentials for identities that have access to vulnerable devices.
  • If you detect web shells or backdoors, rebuild the devices with the latest clean-source image.
  • If restoring from backups, make sure there are no backdoors in the backup configuration.
  • Limit exposure to external attacks by restricting ingress to trusted IPs.

It is also necessary to immediately upgrade to the following firmware versions:

  • NetScaler ADC and NetScaler Gateway 14.1-8.50 and later
  • NetScaler ADC and NetScaler Gateway 13.1-49.15 and later versions of 13.1
  • NetScaler ADC and NetScaler Gateway 13.0-92.19 and later versions of 13.0
  • NetScaler ADC 13.1-FIPS 13.1-37.164 and later versions of 13.1-FIPS
  • NetScaler ADC 12.1-FIPS 12.1-55.300 and later versions of 12.1-FIPS
  • NetScaler ADC 12.1-NDcPP 12.1-55.300 and later versions of 12.1-NdcPP

See also: HTTP/2 Rapid Reset: New DDoS attack exploits as zero-day

Zero-day vulnerabilities

Zero-day vulnerabilities are very dangerous, which is why protective measures must be taken. One of the simplest and most effective ways to reduce the risk of being compromised through vulnerabilities is to regularly update systems. With the release of each new update, manufacturers fix problems and vulnerabilities that they have identified. Since a zero-day vulnerability has been used or disclosed before the release of an update, it is necessary to apply the patch as soon as it becomes available.

In conclusion, zero-day vulnerabilities are a growing threat in the digital landscape. Organizations must always be one step ahead, adopting a proactive stance on their security and reducing the risk of exploiting vulnerabilities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS