cbcvebase.
CVE-2024-12284
published 2025-02-20

CVE-2024-12284: Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
11.92%
95.6th percentile
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

Affected

12 ranges
VendorProductVersion rangeFixed in
citrixnetscaler_agent
citrixnetscaler_agent
citrixnetscaler_agent>= 13.1-4.43 < 13.1-56.1813.1-56.18
citrixnetscaler_agent>= 14.1-4.42 < 14.1-38.5314.1-38.53
citrixnetscaler_console
citrixnetscaler_console
citrixnetscaler_console
citrixxenserver
netscaleragent>= 13.1 < 56.1856.18
netscaleragent>= 14.1 < 38.5338.53
netscalerconsole>= 13.1 < 56.1856.18
netscalerconsole>= 14.1 < 38.5338.53

Detection & IOCsextracted from sources · hover to see the quote

url/stylebook/nitro/v2/config/stylebooks/actions/import
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)"; flow:established,to_server; http.uri; content:"/stylebook/nitro/v2/config/stylebooks/actions/import"; fast_pattern; http.request_body; content:"|22|import|22 3a|"; content:"|22|file_name|22 3a|"; pcre:"/^\s*\x22[^\x22]*?\x2e(?:zip|jar|tar|gz|tgz|bz2)/R"; content:"|22|base64|22|"; http.method; content:"POST"; reference:url,www.rapid7.com/blog/post/cve-2025-4365-cve-unassigned-netscaler-console-sdx-authenticated-arbitrary-file-read-write-fixed/; reference:cve,2024-12284; classtype:web-application-attack; sid:2067197; rev:1; metadata:affected_product Netscaler, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_30, cve CVE_2024_12284, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at 2026_01_30, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
|22|import|22 3a|
bytes
|22|file_name|22 3a|
bytes
|22|base64|22|
  • Exploit targets HTTP POST requests to the StyleBook import endpoint; match on URI path /stylebook/nitro/v2/config/stylebooks/actions/import combined with a JSON body containing 'import', 'file_name', and 'base64' keys, where the filename ends in a compressed archive extension (zip, jar, tar, gz, tgz, bz2).
  • The attack is classified as an authenticated arbitrary file write (privilege escalation); detection should be scoped to authenticated sessions. TLS inspection (SSLDecrypt) is required to inspect the encrypted payload in production environments.
  • MITRE ATT&CK mapping: Tactic TA0001 (Initial Access), Technique T1190 (Exploit Public-Facing Application). Monitor internet-facing NetScaler Console and NetScaler Agent instances for exploitation attempts.
  • ·Fixed versions are NetScaler Console 14.1-38.53+, 13.1-56.18+ and NetScaler Agent 14.1-38.53+, 13.1-56.18+. No workarounds or mitigating factors exist; patching is the only remediation.
  • ·The Snort/Suricata rule (ET sid:2067197) requires TLS decryption to be effective in encrypted deployments; without SSLDecrypt the payload will not be inspectable.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.