惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
月光博客
月光博客
D
DataBreaches.Net
WordPress大学
WordPress大学
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
C
Check Point Blog
F
Fortinet All Blogs
B
Blog
小众软件
小众软件
Vercel News
Vercel News
罗磊的独立博客
有赞技术团队
有赞技术团队

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Critical vulnerabilities in NetScaler ADC exploited in-th...
Merav Bar, Amitai Cohen · 2025-07-06 · via Wiz Blog | RSS feed

On June 17th, 2025, two critical vulnerabilities - CVE-2025-5349 and CVE-2025-5777 - were disclosed in Citrix Netscaler ADC and Netscaler Gateway, enabling unauthorized access to sensitive resources and memory overreads in specific configurations. Due to certain similarities between CVE-2025-5777 and CVE-2023-4966 (AKA “CitrixBleed”), in some publications this vulnerability has been nicknamed “CitrixBleed 2”.

On June 25, 2025, a third critical RCE vulnerability - CVE-2025-6543 - was also disclosed. This flaw affects the same products as above, with the vendor noting that it has been exploited in the wild as a 0-day. Customers are strongly advised to update to the latest fixed versions to mitigate these risks.

What are the vulnerabilities?

CVE-2025-5777: Memory Overread via Crafted HTTP Requests (CVSS 9.3)

CVE-2025-5777 arises from insufficient input validation, leading to memory overreads. While initially described as affecting only the NetScaler Management Interface, Citrix later confirmed that the vulnerability also impacts systems configured as Gateways or AAA virtual servers—a common enterprise deployment for Citrix and RDP remote access. By sending a crafted HTTP request, an unauthenticated remote attacker could leak sensitive memory contents, including session tokens, user credentials, and other confidential artifacts. This vulnerability resembles CVE-2023-4966 (CitrixBleed), where leaked session tokens were used to hijack active remote sessions.

CVE-2025-5349: Improper Access Control on Management Interface (CVSS 8.7)

CVE-2025-5349 is an improper access control vulnerability affecting the NetScaler Management Interface. Exploitation requires network access to specific interfaces such as the NSIP (NetScaler IP), Cluster Management IP, or a local GSLB Site IP. If exploited successfully, attackers could gain unauthorized access to sensitive management functionality, potentially compromising administrative control over affected devices.

CVE-2025-6543: Memory Overflow (CVSSv4 9.2)

CVE-2025-6543 is a critical memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway. While the flaw is described as enabling denial-of-service attacks, it could potentially allow for unauthenticated remote code execution based on its CVSS score, which indicates that the vulnerability severely impacts confidentiality, integrity, and availability. CVE-2025-6543 has been confirmed by Citrix as being exploited in the wild as a 0-day prior to public disclosure.

CVE-2025-6543 affects systems configured as Gateways or AAA virtual servers, and is not directly related to CVE-2025-5777 or CVE-2023-4966.

Wiz Research data: what’s the risk to cloud environments?      

According to Wiz data, 3.5% of cloud environments have resources vulnerable to these vulnerabilities.

What sort of exploitation has been identified in the wild? 

ReliaQuest has reported observing possible evidence of exploitation in the wild of CVE-2025-5777, and a proof-of-concept exploit for the vulnerability was published on July 3rd, 2025. This has since been successfully tested by security teams against vulnerable organizations, indicating that by now threat actors are likely to be including it in their toolkits as well.

Citrix have stated that CVE-2025-6543 was exploited in the wild as a 0-day, but haven’t made further details public. Citrix has advised customers interested in scanning for indicators of compromise to request this information from Citrix customer support.

Which products are affected?

The following products are vulnerable to CVE-2025-5349, CVE-2025-5777 and CVE-2025-6543:

  • NetScaler ADC and Gateway in versions from 14.1 to 14.1-43.56

  • NetScaler ADC and Gateway in versions from 13.1 to 13.1-58.32

  • NetScaler ADC in versions from 13.1-FIPS/NDcPP to 13.1-37.235-FIPS/NDcPP

  • NetScaler ADC in versions from 12.1-FIPS to 12.1-55.328-FIPS

Note: Versions 12.1 and 13.0 are EOL and remain vulnerable without updates.

Which actions should security teams take?

  • It is recommended to upgrade to a patched version as soon as possible. Patches are available for supported versions (13.1 and 14.1), while end-of-life versions (12.1 and 13.0) remain unpatched. Organizations running affected EOL versions are urged to upgrade immediately to supported builds.

  • After upgrading, terminate all active ICA and PCoIP sessions using the following commands:

  • Kevin Beaumont has published a list of IP addresses and domains identified as hosting the affected products - security teams can check if their organizations’ appliances are listed as vulnerable to CVE-2025-5777.

  • Based on their own research of CVE-2025-5777, Horizon3 have recommended checking for entries in ns.log that include non-printable characters, which may indicate successful exploitation of this vulnerability.

  • Given the potential for credential theft via CVE-2025-5777, it is advisable to rotate all potentially exposed passwords.

Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment:

References