Critical Citrix ADC Vulnerability: PoC Released for 0-day Flaw – CVE-2023-3519
August 7, 2023
A proof-of-concept (PoC) for a critical vulnerability, CVE-2023-3519, in Citrix ADC has been made public. This isn't just another security flaw, but a stack-based buffer overflow that has been actively exploited, opening a pathway for unauthenticated attackers to execute remote codes on systems functioning as gateways.
The severity of this vulnerability is underscored by its rating of 9.8 out of 10, due to the low complexity of the attack and the lack of privileges or user interaction needed to exploit it. This vulnerability impacts unpatched Netscaler appliances configured as gateways (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or authentication virtual servers (AAA server).
Citrix addressed this flaw in security updates released on July 18. However, a report by BishopFox on July 21 revealed that approximately 61,000 Citrix appliances on the internet could be at risk, with around 35% (21,000) potentially vulnerable.
The US Cybersecurity and Infrastructure Security Agency (CISA) stated, “In June 2023, threat actors exploited this vulnerability as a zero-day to drop a webshell on a critical infrastructure organization’s NetScaler ADC appliance.” CISA added CVE-2023-3519 to its Known Exploited Vulnerabilities Catalog on July 19, 2023.
Caleb Gross, a security researcher from BishopFox, went beyond just raising the alarm. He wrote a technical advisory, including a PoC code, demonstrating the exploitability of the CVE-2023-3519 flaw. The PoC exploit code is alarmingly straightforward, requiring only three arguments: the target host, the target port, and the URL of a shell script payload. The shellcode cleverly writes a backdoor to `/var/netscaler/logon/a.php` and adjusts the SUID bit on `/bin/sh` so the payload can run as root. The backdoor, made up of a compact PHP payload, initiates `curl
Related News
Latest News
- Critical Vulnerability in PaperCut Software Exposes Unpatched Servers to Remote Code Execution Attacks
- Top Exploited Cybersecurity Vulnerabilities of 2022 Unveiled by FBI, CISA, and NSA
- Milesight Industrial Router Faces Multiple RCE Vulnerabilities: Cisco Talos Report
- Ivanti Reveals Critical Authentication Bypass Vulnerability in MobileIron Core
- Ongoing Attacks Breach Over 640 Citrix Servers Exploiting Critical RCE Vulnerability
Like what you see?
Get a digest of headlines, vulnerabilities, risk context, and more delivered to your inbox.