Interestana
Home/News/Citrix Urges Immediate Patch for Critical NetScaler Vulnerability
BleepingComputer••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Citrix Urges Immediate Patch for Critical NetScaler Vulnerability

Citrix has issued a critical alert to IT administrators, urging them to immediately patch systems affected by a newly discovered vulnerability in its NetScaler Application Delivery Controller (ADC) networking appliances and NetScaler Gateway secure remote access solutions. This vulnerability, identified as CVE-2023-4966, is classified as a critical remote code execution (RCE) flaw, meaning an attacker could potentially execute arbitrary code on a vulnerable system without prior authentication. The company has provided specific guidance and remediation steps for administrators to mitigate the risk.

The vulnerability impacts NetScaler ADC and NetScaler Gateway versions 13.1 and 13.0. Citrix has released updated versions, 13.1-37.159 and 13.0-88.12, for NetScaler ADC, and 13.1-37.159 and 13.0-88.12 for NetScaler Gateway, which address this security issue. For customers running older, unsupported versions, Citrix recommends upgrading to a supported release. The company has also highlighted that this vulnerability is distinct from the previously disclosed critical RCE vulnerability (CVE-2023-4967) affecting NetScaler ADC and NetScaler Gateway, which was patched in October 2023. The earlier vulnerability also allowed for unauthenticated remote code execution and was considered a high-severity threat.

NetScaler ADC is a comprehensive application delivery and load balancing solution designed to optimize application performance, availability, and security for enterprises. NetScaler Gateway provides secure remote access to applications and data, enabling users to connect to corporate resources from outside the network. The presence of an RCE vulnerability in these products poses a significant risk, as successful exploitation could allow attackers to gain full control over the affected appliances. This control could then be leveraged to access sensitive data, disrupt network operations, or launch further attacks within an organization's infrastructure.

Citrix has emphasized that while they are not aware of any active exploitation of CVE-2023-4966 at the time of their advisory, the critical nature of RCE vulnerabilities necessitates prompt action. Administrators are advised to apply the necessary patches as soon as possible to protect their environments. The company's security advisories typically include detailed information about affected product versions, the severity of the vulnerability, and the recommended mitigation steps. Organizations relying on NetScaler products for their network infrastructure and remote access capabilities are strongly encouraged to consult Citrix's official security bulletins for the most up-to-date information and patching instructions to prevent potential security breaches.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next