Menu Close

Citrix Products Could Allow for Remote Code Execution – TLP: CLEAR

TLP:CLEAR
MS-ISAC CYBERSECURITY ADVISORY

MS-ISAC ADVISORY NUMBER:
2023-080

DATE(S) ISSUED:
07/18/2023

SUBJECT:
Multiple Vulnerabilities in Citrix Products Could Allow for Remote Code Execution

OVERVIEW:
Multiple vulnerabilities have been discovered in Citrix products, the most severe of which could allow for remote code execution. Citrix ADC performs application-specific traffic analysis to intelligently distribute, optimize, and secure Layer 4 – Layer 7 network traffic for web applications. Citrix Gateway is used to consolidate remote access infrastructure and provide single sign-on across all applications whether in a data center, in a cloud, or if the apps are delivered as SaaS apps. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

THREAT INTELLIGENCE:
Citrix have advised in their security bulletin that exploitation of CVE-2023-3519 against vulnerable appliances has been observed in the wild.

SYSTEMS AFFECTED:

  • NetScaler ADC and NetScaler Gateway prior to 13.1-49.13  and later releases
  • NetScaler ADC and NetScaler Gateway prior to 13.0-91.13  and later releases of 13.0 
  • NetScaler ADC prior to 13.1-FIPS 13.1-37.159 and later releases of 13.1-FIPS 
  • NetScaler ADC prior to 12.1-FIPS 12.1-55.297 and later releases of 12.1-FIPS 
  • NetScaler ADC prior to 12.1-NDcPP 12.1-55.297 and later releases of 12.1-NDcPP

 

RISK:
Government:

  • Large and medium government entities: High
  • Small government entities: Medium

 

Businesses:

  • Large and medium business entities: High
  • Small business entities: Medium

Home users: Low

TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Citrix products, the most severe of which could allow for remote code execution. Details of these vulnerabilities are as follows:

Tactic: Execution (TA0002)

Technique: Exploitation for Client Execution (T1203):

  • CVE-2023-3519: Unauthenticated remote code execution           

Details of lower-severity vulnerabilities are as follows:

  • CVE-2023-3466: Reflected Cross-Site Scripting (XSS)
    • Prerequisite : Requires victim to access an attacker-controlled link in the browser while being on a network with connectivity to the NSIP     
  • CVE-2023-3467: Privilege Escalation to root administrator (nsroot)
    • Prerequisite : Authenticated access to NSIP or SNIP with management interface access

Successful exploitation of the most severe of these vulnerabilities could allow for remote compromise by the user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

RECOMMENDATIONS:

We recommend the following actions be taken:

  • Apply appropriate updates provided by Citrix to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.

·          

    • Safeguard 9.1: Ensure Use of Only Fully Supported Browsers and Email Clients: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
  • Restrict execution of code to a virtual environment on or in transit to an endpoint system. (M1048: Application Isolation and Sandboxing)
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
    • Safeguard 10.5:  Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017: User Training)
    • Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.

REFERENCES:

Citrix: 
https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467 

CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3466
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3467
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3519 

Multi-State Information Sharing and Analysis Center (MS-ISAC)
Elections Infrastructure Information Sharing and Analysis Center (EI-ISAC)
31 Tech Valley Drive
East Greenbush, NY 12061

24×7 Security Operations Center
SOC@cisecurity.org – 1-866-787-4722

TLP:CLEAR
www.cisa.gov/tlp
Information may be distributed without restriction, subject to standard copyright rules.

Center for Internet Security

Northeast Headquarters | 31 Tech Valley Drive | East Greenbush, NY 12061 | Phone: 518-266-3460