An exploit PoC for the “ Citrix Bleed ” vulnerability, tracked as CVE-2023-4966 , shows that it allows attackers to retrieve authentication session cookies from vulnerable Citrix NetScaler ADC and NetScaler Gateway appliances
See also: Citrix: Immediate action to fix critical issue in NetScaler

CVE-2023-4966 is a serious information disclosure issue that can be exploited remotely and which Citrix patched on October 10, without providing many details.
On October 17, Mandiant revealed that this vulnerability was exploited as a zero-day in limited attacks since August 2023.
This Monday, Citrix issued another warning to administrators of NetScaler ADC and Gateway appliances, encouraging them to immediately update the security flaw, as its exploitation has begun to increase.
Today, Assetnote researchers shared more details about the CVE-2023-4966 exploitation method and published a PoC exploit on GitHub to demonstrate their findings and help those who want to check their vulnerability.
CVE-2023-4966 Citrix Bleed is an uncontrolled buffer overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances , which are used for load balancing, firewall protection, traffic management, VPN , and user authentication.
Analyzing the non-updated (13.1-48.47) and updated (13.1-49.15) versions of NetScaler, Assetnote identified 50 changes in functionality.
Among these functions, the researchers discovered two ('ns_aaa_oauth_send_openid_config' and 'ns_aaa_oauthrp_send_openid_config') that contained additional bounds checks before generating a response.
See also: Recently fixed Citrix NetScaler bug was used as a zero-day

These functions use 'snprintf' to insert the appropriate data into the generated JSON payload for the OpenID regulatory information. In the pre-release version of the update, the response is sent immediately without checks.
The vulnerability arises from the return value of the snprintf function, which could lead to a buffer over-read if exploited. The patched version ensures that a response will only be sent if snprintf returns a value less than 0x20000.
By exploiting the vulnerability thousands of times for testing, analysts consistently found a 32-65-byte hex string, which is a “session cookie.”.
Retrieving this cookie makes it possible for attackers to monitor accounts and gain unrestricted access to vulnerable devices
Now that a PoC for CVE-2023-4966 is publicly available, it is expected that attacks by malicious users on Citrix Netscaler devices to gain initial access to corporate networks will increase.
As these types of vulnerabilities are often used for ransomware and data theft, it is strongly recommended that system administrators immediately install updates to patch the vulnerability.
See also: Citrix NetScaler: Hackers steal credentials from its login pages
The best practice for protecting against the Citrix Bleed exploit is to update your Citrix software on a regular basis. Citrix regularly releases updates and patches for any vulnerabilities that attackers may exploit. Therefore, it is important to regularly check for updates and install them promptly to protect your system.
Additionally, it is a good practice to implement strict security policies for access to Citrix NetScaler. This can include using complex passwords, enabling two-factor authentication, and limiting access to authorized users only.
Finally, it is important to educate your users about security threats and the proper use of Citrix NetScaler. Users should be aware of the risks and follow predefined security policies, such as avoiding clicking on suspicious links or using secure passwords.
Source: bleepingcomputer
