Citrix reminded admins today that they must take additional measures after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to secure vulnerable devices against attacks. Besides applying the necessary security updates, they're also advised to wipe all previous user sessions and terminate all active ones. This is a crucial step, seeing that attackers behind ongoing Citrix Bleed exploitation have been stealing authentication tokens, allowing them to access compromised devices even after they have been patched. Citrix patched the flaw in early October, but Mandiant revealed that it has been under active exploitation as a zero-day since at least late August 2023. Mandiant also warned that compromised NetScaler sessions persist after patching, enabling attackers to move laterally across the network or compromise other accounts depending on the compromised accounts' permissions. "If you are using any of the affected builds listed in the security bulletin, you should upgrade immediately by installing the updated versions. After you upgrade, we recommend that you remove any active or persistent sessions," Citrix said today. This is the second time the company has warned customers to kill all active and persistent sessions using the following commands: Today, CISA and the FBI cautioned that the LockBit ransomware gang is exploiting the Citrix Bleed security flaw in a joint advisory with the Multi-State Information Sharing & Analysis Center (M...
Citrix warns admins to kill NetScaler user sessions to block hackers
BleepingComputer
·Sergiu Gatlan
·Published Nov 21, 2023
·Updated
Affected Software
1 affected component
Citrix NetScaler