Citrix has released patches for two vulnerabilities affecting Citrix Hypervisor, one of which is the serious “ Reptar ” vulnerability affecting Intel processors for desktop and server systems
See also: LockBit ransomware: Exploits Citrix Bleed vulnerability in attacks

Citrix Hypervisor (formerly XenServer) is an enterprise-grade platform for deploying and managing virtual environments.
The hotfixes address vulnerabilities listed as CVE-2023-23583 and CVE-2023-46835. The former is a security issue that Intel recently disclosed and affects the 'Ice Lake' (2019) and later generations of processors.
Known as the “Redundant Prefix Issue,” the vulnerability involves executing a specific command (REP MOVSB) with a redundant REX prefix, which can lead to system instability, crashes, or, in rare cases, minimal privilege escalation.
Intel has released a new microcode that fixes the issue and recommends an immediate update to mitigate this issue. However, the hardware manufacturer also notes that the real-world exploitability probability for CVE-2023-23583 is low.
“While this is not an issue in the Citrix Hypervisor product itself, we have included updated Intel microcode to address this CPU hardware issue,” the update.
See also: Citrix Bleed: Hackers gain control of NetScaler accounts
Google researchers, led by Tavis Ormandy, independently discovered Reptar some time ago. Ormandy says that while it is known how to “corrupt the system state in such a way as to cause machine control errors,” a way to exploit this error to achieve privilege escalation is still being sought.
The second vulnerability that Citrix has patched is CVE-2023-46835, which affects Citrix Hypervisor 8.2 CU1 LTSR. It can be exploited to allow malicious privileged code in a guest virtual machine (VM) to compromise an AMD-based host via a PCI device passthrough.
This issue only affects guest VM hosts that use an AMD and also use a passed-through PCI device.
Instructions on how to apply the update for the aforementioned issues can be found on this page in the Citrix Knowledge Center.
See also: Citrix: Immediate action to fix critical issue in NetScaler
There are known issues and limitations with the hotfix for the Intel Reptar processor vulnerability in Citrix Hypervisor. One of the known issues is that system performance may decrease after applying the hotfix. Additionally, some applications or features may not function correctly after installing the hotfix.
It is important to check the compatibility of your applications and ensure that you have taken all necessary protection measures before applying the hotfix.
Source: bleepingcomputer
