Vulnerability record · CVE-2023-4966 · published 10 October 2023
CVE-2023-4966: Citrix NetScaler ADC and Gateway buffer overflow leaks session tokens
Citrix · Netscaler Application Delivery Controller
A memory buffer overflow in NetScaler ADC and NetScaler Gateway, when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, allows sensitive information disclosure. The flaw, tracked as CitrixBleed, leaks session tokens that attackers can reuse to bypass authentication. It matters because the affected appliances are internet-facing remote access points and the vulnerability is confirmed exploited in the wild.
Description
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityActively exploited in the wild, listed in CISA KEV with known ransomware use, and near-maximum EPSS probability on internet-facing remote access appliances.
What it is
A memory buffer overflow in NetScaler ADC and NetScaler Gateway, when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, allows sensitive information disclosure. The flaw, tracked as CitrixBleed, leaks session tokens that attackers can reuse to bypass authentication. It matters because the affected appliances are internet-facing remote access points and the vulnerability is confirmed exploited in the wild.
Impact
An unauthenticated attacker can read sensitive memory contents, including session tokens, and use them to hijack authenticated sessions. This can grant access to internal resources and, per CISA, has been linked to ransomware deployment.
Attack surface
Reachable over the network via the affected Gateway or AAA virtual server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only appliances configured in those specific roles are exposed.
Exploitation
CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS probability is 0.99999 (99.998th percentile). Public proof-of-concept code for session token leakage is referenced.
What to do
- Apply the vendor security update for NetScaler ADC and NetScaler Gateway per Citrix advisory CTX579459.
- After patching, kill all active and persistent sessions as instructed by Citrix and CISA.
- If patching is not immediately possible, apply vendor mitigations or discontinue use of the affected Gateway/AAA virtual server configuration.
- Restrict management and Gateway access to trusted networks where feasible and monitor for anomalous session reuse.
Detection
- Hunt for unusual session token reuse or authentication from unexpected source IPs against NetScaler Gateway.
- Review NetScaler logs for memory disclosure indicators or abnormal HTTP responses from the Gateway/AAA virtual server.
- Monitor for post-exploitation activity consistent with ransomware staging on systems reachable through the appliance.
- Correlate NetScaler session identifiers with downstream authentication events to spot hijacked sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-4966 to the Known Exploited Vulnerabilities catalog on 18 October 2023 as "Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable. Federal deadline 8 November 2023.
Ransomware crews whose documented playbooks reference this CVE: