Site icon TheCyberThrone

Mandiant Advise on Citrix NetScaler ADC Vulnerability

Advertisements

Mandiant has advised security teams that only applying the patch that was released to fix a recent Citrix NetScaler ADC and Gateway vulnerability was not enough they need to close all active sessions to ensure that the vulnerable code is not resident in memory.   

The vulnerability CVE-2023-4966, which is rated a critical 9.4 by Citrix, lets attackers steal the token of recently connected users, allowing the attacker to gain access to whatever resources the user has permissions to access in Citrix.

Advertisements

Mandiant is observing that threat actors can perform credential harvesting, move laterally in the victim’s network via RDP, and conduct reconnaissance of the victim’s environment. Mandiant also said it’s investigating intrusions across multiple verticals, including legal and professional services, technology, and government organizations in the Americas, Europe, the Middle East and Africa, and the Asia-Pacific and Japan regions.

Mandiant in its blogspot outlined the following techniques for security teams to consider to identify potential exploitation of CVE-2023-4966 and session hijacking:

Advertisements

Recommendation from security experts

  1. Enhanced monitoring and analysis
  2. Historical log review
  3. Registry analysis on Citrix Virtual Delivery Agent
  4. Memory core dump analysis
  5. Post-exploitation detection
  6. Patching
  7. Proactive threat hunting
  8. Attribution analysis
Exit mobile version