CVE-2023-3467
published 2023-07-19CVE-2023-3467: Privilege Escalation to root administrator (nsroot)
PriorityP278high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.10%
79.3th percentile
Privilege Escalation to root administrator (nsroot)
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adc | — | — |
| citrix | citrix_gateway | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_adc | >= 12.1-FIPS < 55.297 | 55.297 |
| citrix | netscaler_adc | >= 12.1-NDcPP < 55.297 | 55.297 |
| citrix | netscaler_adc | >= 13.0 < 91.13 | 91.13 |
| citrix | netscaler_adc | >= 13.1 < 49.13 | 49.13 |
| citrix | netscaler_adc | >= 13.1-FIPS < 37.159 | 37.159 |
| citrix | netscaler_application_delivery_controller | — | — |
| citrix | netscaler_application_delivery_controller | >= 12.1 < 12.1-55.297 | 12.1-55.297 |
| citrix | netscaler_application_delivery_controller | >= 13.0 < 13.0-91.13 | 13.0-91.13 |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-37.159 | 13.1-37.159 |
| citrix | netscaler_application_delivery_controller | >= 13.1 < 13.1-49.13 | 13.1-49.13 |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_gateway | >= 13.0 < 91.13 | 91.13 |
| citrix | netscaler_gateway | >= 13.0 < 13.0-91.13 | 13.0-91.13 |
| citrix | netscaler_gateway | >= 13.1 < 49.13 | 49.13 |
| citrix | netscaler_gateway | >= 13.1 < 13.1-49.13 | 13.1-49.13 |
| citrix | xenserver | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Palo Alto Networks Threat Prevention signature 94145 can help block attacks related to this CVE cluster (CVE-2023-3519/3466/3467). ↗
- →CVE-2023-3467 requires authenticated access to NSIP or SNIP with management interface access; monitor for unexpected privilege escalation to nsroot on NetScaler management interfaces. ↗
- ·CVE-2023-3467 exploitation requires the attacker to already have authenticated access to the NSIP or SNIP with management interface access — it is not unauthenticated. ↗
- ·Only customer-managed (not Citrix-managed) NetScaler ADC and NetScaler Gateway appliances are vulnerable; Citrix-managed instances have already been mitigated. ↗
- ·NetScaler ADC and NetScaler Gateway version 12.1 is End of Life (EOL) and will not receive patches; customers must upgrade to a supported version. ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
vendor_citrix·2023-07-18·CVSS 6.1
CVE-2023-3466 [MEDIUM] CWE-20 Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
Pre-requisites CWE CVE-2023-3466 Citrix ADC, Citrix Gateway Reflected Cross-Site Scripting (XSS) Requires victim to access an attacker-controlled link in the browser while being on a network with connectivity to the NSIP CWE-20 CVE-2023-3467 Citrix ADC, Citrix Gateway Privilege Escalation to root administrator (nsroot) Authenticated access to NSIP or SNIP with management interface access CWE-269 CVE-2023-3519 Citrix ADC, Citrix Gateway Unauthenticated remote code execution Appliance must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server CWE-94 Instructions Exploits of CVE-2023-3519 on unmitigated appliances have been observed. Cloud Software Group
GHSA
GHSA-rq56-q73v-5g57: Privilege Escalation to root administrator (nsroot)
ghsa_unreviewed·2023-07-19
CVE-2023-3467 [HIGH] CWE-269 GHSA-rq56-q73v-5g57: Privilege Escalation to root administrator (nsroot)
Privilege Escalation to root administrator (nsroot)
VulnCheck
Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege Escalation
vulncheck·2023·CVSS 8.0
CVE-2023-3467 [HIGH] Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege Escalation
Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege Escalation
Privilege Escalation to root administrator (nsroot)
Affected: Citrix NetScaler ADC and NetScaler Gateway
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.sentinelone.com/resources/watchtower-end-of-year-report-2023/; https://www.trendmicro.com/en_us/research/24/k/lodeinfo-campaign-of-earth-kasha.html; https://horizon3.ai/intelligence/blogs/from-patch-tuesday-to-pentest-wednesday-how-a-global-chemical-manufacturer-de-risked-a-2b-merger/
No detection rules found.
No public exploits indexed.
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Trendmicro
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
blogs_trendmicro·2024-11-19
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
APT und gezielte Angriffe
## Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. We have identified a new campaign connected to this group with significant updates to their strategy, tactics, and arsenals.
By: Trend Micro Nov 19, 2024 Read time: ( words)
Save to Folio
This blog is based on a presentation by the authors at Virus Bulletin 2024 .
Possible Cracked Version of Cobalt Strike
In the early incidents above, Earth Kasha also used Cobalt Strike. Like other adversaries, Cobalt Strike is designed to be executed only in memory. In this case, Earth Kasha used a shellcode loader written in Go, which
Trendmicro
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
blogs_trendmicro·2024-11-19
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
APT & Targeted Attacks
# Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. We have identified a new campaign connected to this group with significant updates to their strategy, tactics, and arsenals.
By: Trend Micro
2024/11/19
Read time: ( words)
Save to Folio
This blog is based on a presentation by the authors at Virus Bulletin 2024.
## Introduction
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. While some vendors suspect that the actor using LODEINFO might be APT10, we don’t have enough evidence to fully support t
Trendmicro
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
blogs_trendmicro·2024-11-19
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
APT & Targeted Attacks
## Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. We have identified a new campaign connected to this group with significant updates to their strategy, tactics, and arsenals.
By: Trend Micro Nov 19, 2024 Read time: ( words)
Save to Folio
This blog is based on a presentation by the authors at Virus Bulletin 2024 .
Possible Cracked Version of Cobalt Strike
In the early incidents above, Earth Kasha also used Cobalt Strike. Like other adversaries, Cobalt Strike is designed to be executed only in memory. In this case, Earth Kasha used a shellcode loader written in Go, which we
Trendmicro
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
blogs_trendmicro·2024-11-19
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
APT y ataques dirigidos
## Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. We have identified a new campaign connected to this group with significant updates to their strategy, tactics, and arsenals.
By: Trend Micro Nov 19, 2024 Read time: ( words)
Save to Folio
This blog is based on a presentation by the authors at Virus Bulletin 2024 .
Possible Cracked Version of Cobalt Strike
In the early incidents above, Earth Kasha also used Cobalt Strike. Like other adversaries, Cobalt Strike is designed to be executed only in memory. In this case, Earth Kasha used a shellcode loader written in Go, which w
Trendmicro
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
blogs_trendmicro·2024-11-19
Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
APT & Targeted Attacks
## Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella
LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. We have identified a new campaign connected to this group with significant updates to their strategy, tactics, and arsenals.
By: Trend Micro 2024/11/19 Read time: ( words)
Save to Folio
This blog is based on a presentation by the authors at Virus Bulletin 2024 .
Possible Cracked Version of Cobalt Strike
In the early incidents above, Earth Kasha also used Cobalt Strike. Like other adversaries, Cobalt Strike is designed to be executed only in memory. In this case, Earth Kasha used a shellcode loader written in Go, which we d
Unit42
Threat Brief: RCE Vulnerability CVE-2023-3519 on Customer-Managed Citrix Servers
blogs_unit42·2023-07-28·CVSS 8.3
CVE-2023-3519 [HIGH] Threat Brief: RCE Vulnerability CVE-2023-3519 on Customer-Managed Citrix Servers
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: RCE Vulnerability CVE-2023-3519 on Customer-Managed Citrix Servers
Unit 42
Published: July 28, 2023
High Profile Threats
Threat Research
Vulnerabilities
Citrix
Citrix Netscaler
CVE-2023-3466
CVE-2023-3467
CVE-2023-3519
## Executive Summary
On July 18, 2023, Citrix published a security bulletin for vulnerabilities affecting their NetScaler ADC and NetScaler Gateway products. When these appliances are configured as a gateway or authentication server and managed by a customer (i.e., not Citrix-managed) they can be vulnerable to remote code execution initiated by an attacker. Vulnerabilities on Citrix-managed servers have already been mitigated.
Citrix states that they have observed attacks targeti
Unit42
Threat Brief: RCE Vulnerability CVE-2023-3519 on Customer-Managed Citrix Servers
blogs_unit42·2023-07-28·CVSS 8.3
CVE-2023-3519 [HIGH] Threat Brief: RCE Vulnerability CVE-2023-3519 on Customer-Managed Citrix Servers
## Executive Summary
On July 18, 2023, Citrix published a security bulletin for vulnerabilities affecting their NetScaler ADC and NetScaler Gateway products. When these appliances are configured as a gateway or authentication server and managed by a customer (i.e., not Citrix-managed) they can be vulnerable to remote code execution initiated by an attacker. Vulnerabilities on Citrix-managed servers have already been mitigated.
Citrix states that they have observed attacks targeting CVE-2023-3519 against appliances that haven’t been patched. The Cybersecurity and Infrastructure Security Agency (CISA) has also released an advisory detailing an attack using this vulnerability.
Palo Alto Networks customers receive protections from and mitigations for CVE-2023-3519 in the following ways:
-
Tenable
CVE-2023-3519: Critical RCE in Netscaler ADC (Citrix ADC) and Netscaler Gateway (Citrix Gateway)
blogs_tenable·2023-07-18·CVSS 9.8
[CRITICAL] CVE-2023-3519: Critical RCE in Netscaler ADC (Citrix ADC) and Netscaler Gateway (Citrix Gateway)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
Zscaler
CISO Monthly Roundup, August 2023: Deep analysis of Ducktail, Statc Stealer, JanelaRAT, Agniane Stealer, insights on SEC cybersecurity policies, and NetScaler security advisories | CXO Revolutionaries
blogs_zscaler
CISO Monthly Roundup, August 2023: Deep analysis of Ducktail, Statc Stealer, JanelaRAT, Agniane Stealer, insights on SEC cybersecurity policies, and NetScaler security advisories | CXO Revolutionaries
## CISO Monthly Roundup, August 2023: Deep analysis of Ducktail, Statc Stealer, JanelaRAT, Agniane Stealer, insights on SEC cybersecurity policies, and NetScaler security advisories
Deepen Desai
Contributor
Zscaler
## Sep 5, 2023
The August CISO Monthly Roundup features ThreatLabz research on DuckTail, Static Stealer, JanelaRAT, and more.
The CISO Monthly Roundup provides the latest threat research from the ThreatLabz team, along with CISO insights on other cyber-related subjects. Over the past month, ThreatLabz deconstructed Ducktail operations, analyzed Statc Stealer, JanelaRAT, Agniane Stealer, provided insights on SEC cybersecurity policies, and issued NetScaler security advisories.
## A deep dive into DuckTail
In May, Zscaler ThreatLabz began an intensive three-month analysis
2023-07-19
Published
Exploited in the wild