CVE-2024-12284
published 2025-02-20CVE-2024-12284: Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
11.92%
95.6th percentile
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | netscaler_agent | — | — |
| citrix | netscaler_agent | — | — |
| citrix | netscaler_agent | >= 13.1-4.43 < 13.1-56.18 | 13.1-56.18 |
| citrix | netscaler_agent | >= 14.1-4.42 < 14.1-38.53 | 14.1-38.53 |
| citrix | netscaler_console | — | — |
| citrix | netscaler_console | — | — |
| citrix | netscaler_console | — | — |
| citrix | xenserver | — | — |
| netscaler | agent | >= 13.1 < 56.18 | 56.18 |
| netscaler | agent | >= 14.1 < 38.53 | 38.53 |
| netscaler | console | >= 13.1 < 56.18 | 56.18 |
| netscaler | console | >= 14.1 < 38.53 | 38.53 |
Detection & IOCsextracted from sources · hover to see the quote
url/stylebook/nitro/v2/config/stylebooks/actions/import
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)"; flow:established,to_server; http.uri; content:"/stylebook/nitro/v2/config/stylebooks/actions/import"; fast_pattern; http.request_body; content:"|22|import|22 3a|"; content:"|22|file_name|22 3a|"; pcre:"/^\s*\x22[^\x22]*?\x2e(?:zip|jar|tar|gz|tgz|bz2)/R"; content:"|22|base64|22|"; http.method; content:"POST"; reference:url,www.rapid7.com/blog/post/cve-2025-4365-cve-unassigned-netscaler-console-sdx-authenticated-arbitrary-file-read-write-fixed/; reference:cve,2024-12284; classtype:web-application-attack; sid:2067197; rev:1; metadata:affected_product Netscaler, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_30, cve CVE_2024_12284, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, updated_at 2026_01_30, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
|22|import|22 3a|
bytes
|22|file_name|22 3a|
bytes
|22|base64|22|
- →Exploit targets HTTP POST requests to the StyleBook import endpoint; match on URI path /stylebook/nitro/v2/config/stylebooks/actions/import combined with a JSON body containing 'import', 'file_name', and 'base64' keys, where the filename ends in a compressed archive extension (zip, jar, tar, gz, tgz, bz2).
- →The attack is classified as an authenticated arbitrary file write (privilege escalation); detection should be scoped to authenticated sessions. TLS inspection (SSLDecrypt) is required to inspect the encrypted payload in production environments.
- →MITRE ATT&CK mapping: Tactic TA0001 (Initial Access), Technique T1190 (Exploit Public-Facing Application). Monitor internet-facing NetScaler Console and NetScaler Agent instances for exploitation attempts.
- ·Fixed versions are NetScaler Console 14.1-38.53+, 13.1-56.18+ and NetScaler Agent 14.1-38.53+, 13.1-56.18+. No workarounds or mitigating factors exist; patching is the only remediation. ↗
- ·The Snort/Suricata rule (ET sid:2067197) requires TLS decryption to be effective in encrypted deployments; without SSLDecrypt the payload will not be inspectable.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
NetScaler Console and NetScaler Agent Security Bulletin for CVE-2024-12284
vendor_citrix·CVSS 8.8
CVE-2024-12284 [HIGH] CWE-269 NetScaler Console and NetScaler Agent Security Bulletin for CVE-2024-12284
NetScaler Console and NetScaler Agent Security Bulletin for CVE-2024-12284
of Problem A vulnerability has been discovered in NetScaler Console (formerly NetScaler ADM) and NetScaler Agent. Refer to below for further details:
CVE References: CVE-2024-12284
Affected Products: NetScaler Agent, NetScaler Console, XenServer
Severity: High
CVSS Score: 8.8
Remediation:
Cloud Software Group strongly urges customers of NetScaler Console and NetScaler Agent to install the relevant updated versions as soon as possible: NetScaler Console 14.1-38.53 and later releases NetScaler Console 13.1-56.18 and later releases of 13.1 NetScaler Agent 14.1-38.53 and later releases NetScaler Agent 13.1-56.18 and later releases of 13.1 Workarounds/ Mitigating Factors None
GHSA
GHSA-4g7p-889h-qvww: Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows
ghsa_unreviewed·2025-02-20
CVE-2024-12284 [HIGH] CWE-269 GHSA-4g7p-889h-qvww: Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
Suricata
ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)
suricata·2026-01-30·CVSS 8.8
CVE-2024-12284 [HIGH] ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)
ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Citrix Netscaler Console Authenticated Arbitrary File Write (CVE-2024-12284)"; flow:established,to_server; http.uri; content:"/stylebook/nitro/v2/config/stylebooks/actions/import"; fast_pattern; http.request_body; content:"|22|import|22 3a|"; content:"|22|file_name|22 3a|"; pcre:"/^\s*\x22[^\x22]*?\x2e(?:zip|jar|tar|gz|tgz|bz2)/R"; content:"|22|base64|22|"; http.method; content:"POST"; reference:url,www.rapid7.com/blog/post/cve-2025-4365-cve-unassigned-netscaler-console-sdx-authenticated-arbitrary-file-read-write-fixed/; reference:cve,2024-12284; classtype:web-application-attack; sid:2067197; rev:1; metadata:affected_product
No public exploits indexed.
No writeups or analysis indexed.
2025-02-20
Published