Today, CISA ordered U.S. federal agencies to secure their systems against three recently patched Citrix NetScaler and Google Chrome zero-days actively exploited in attacks, pushing for a Citrix RCE bug to be patched within a week. The cybersecurity agency added the flaws to its Known Exploited Vulnerabilities Catalog today, saying that such vulnerabilities are "frequent attack vectors for malicious cyber actors" that pose "significant risks to the federal enterprise." Citrix urged customers on Tuesday to immediately patch Internet-exposed Netscaler ADC and Gateway appliances against the CVE-2023-6548 code injection vulnerability and the CVE-2023-6549 buffer overflow impacting the Netscaler management interface that could be exploited for remote code execution and denial-of-service attacks, respectively. Those who can't immediately install the security updates can block network traffic to affected instances and ensure they're not accessible online as a temporary workaround. According to the Shadowserver threat monitoring platform, more than 51,000 Netscaler appliances are exposed online right now, with only 1,500 having their management interfaces accessible over the Internet. CISA also added the CVE-2024-0519 out-of-bounds memory access in the Chromium V8 JavaScript engine to its KEV list today. This is the first Chrome zero-day exploited in the wild patched by Google this year. After their inclusion in CISA's KEV list, U.S. Federal Civilian Executive Branch Agencies (FCEB) ...
CISA pushes federal agencies to patch Citrix RCE within a week
BleepingComputer
·Sergiu Gatlan
·Published Jan 17, 2024
·Updated
Affected Software
2 affected components
Citrix NetScaler
Google Chrome
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA urging U.S. federal agencies to patch critical vulnerabilities in Citrix NetScaler and Google Chrome.
2
What security implications are discussed?
The article highlights the risks of unpatched zero-day vulnerabilities that are actively being exploited in attacks.
3
What products or software are affected?
The affected products include Citrix NetScaler and Google Chrome.
4
What is the recommended action for federal agencies?
CISA recommends that federal agencies patch the Citrix RCE vulnerability within a week.
5
Why is timely patching important according to CISA?
Timely patching is crucial to prevent exploitation of known vulnerabilities that can lead to unauthorized access and data breaches.