cbcvebase.
CVE-2023-4966
published 2023-10-10

CVE-2023-4966: Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA…

PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-11-08
Exploited in the wild
EPSS
100.00%
100.0th percentile
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Affected

22 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adc
citrixcitrix_gateway
citrixnetscaler_adc
citrixnetscaler_adc>= 12.1-FIPS < 55.30055.300
citrixnetscaler_adc>= 12.1-NDcPP < 55.30055.300
citrixnetscaler_adc>= 13.0 < 92.1992.19
citrixnetscaler_adc>= 13.1 < 49.1549.15
citrixnetscaler_adc>= 13.1-FIPS < 37.16437.164
citrixnetscaler_adc>= 14.1 < 8.508.50
citrixnetscaler_application_delivery_controller>= 12.1 < 12.1-55.30012.1-55.300
citrixnetscaler_application_delivery_controller>= 13.0 < 13.0-92.1913.0-92.19
citrixnetscaler_application_delivery_controller>= 13.1 < 13.1-37.16413.1-37.164
citrixnetscaler_application_delivery_controller>= 13.1 < 13.1-49.1513.1-49.15
citrixnetscaler_application_delivery_controller>= 14.1 < 14.1-8.5014.1-8.50
citrixnetscaler_gateway
citrixnetscaler_gateway>= 13.0 < 92.1992.19
citrixnetscaler_gateway>= 13.0 < 13.0-92.1913.0-92.19
citrixnetscaler_gateway>= 13.1 < 49.1549.15
citrixnetscaler_gateway>= 13.1 < 13.1-49.1513.1-49.15
citrixnetscaler_gateway>= 14.1 < 8.508.50
citrixnetscaler_gateway>= 14.1 < 14.1-8.5014.1-8.50
citrixxenserver

Detection & IOCsextracted from sources · hover to see the quote

commandkill aaa session -all
commandkill icaconnection -all
commandkill rdp connection -all
commandkill pcoipConnection -all
commandclear lb persistentSessions
hash21d709b0593c19ad2798903ae02de7ecdbf8033b3e791b70d7595bca64b99721
hashaf8a072f20c8e647f53eb735528f070d
hash032f2e845d2b9832c7845bc6a7de650ee2148891c8ee442fe3f3a8478e588dbe
hasha5cc0738a563489458f6541c3d3dc722
hashb9ddbd1a4cec61e6b022a275d66312b5b676f9a0a9537a7708de9aa8ce34de59
hash3b100bdcd61bb1da816cd7eaf9ef13ba
filenameobfs.ps1
filenamerecon.ps1
filenamesvhost.exe
filenamescvhost.exe
  • Stolen session tokens from CVE-2023-4966 remain valid even after patching; organizations must explicitly kill all active and persistent sessions using Citrix CLI commands post-patch to prevent authentication bypass.
  • Post-exploitation, Storm-0501 deployed RMM tools (Level.io, AnyDesk, NinjaOne) for persistence; alert on installation or execution of these tools on systems following a Citrix ADC compromise event.
  • Rclone renamed to svhost.exe or scvhost.exe used for data exfiltration to MegaSync; detect Rclone-like command-line patterns (copy, --transfers, --multi-thread-streams) executed from binaries with Windows system process names.
  • Cobalt Strike Beacons used by Storm-0501 post-CVE-2023-4966 exploitation were .dll and .ocx files launched via rundll32.exe and regsvr32.exe respectively; hunt for these file types loaded by these LOLBins.
  • CVE-2023-4966 exploitation was observed in the wild since August 2023, before the October 10 patch; treat any NetScaler ADC/Gateway running vulnerable versions as potentially already compromised and investigate session token theft.
  • ·CVE-2023-4966 only affects NetScaler ADC and Gateway devices configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; devices not in these configurations are not vulnerable.
  • ·Citrix-managed cloud services and Citrix-managed Adaptive Authentication are NOT affected; only customer-managed NetScaler appliances are impacted.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck9.4CRITICAL
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.