Citrix NetScaler takeovers possible with new exploit

Vulnerable Citrix NetScaler Application Delivery Controller and NetScaler Gateway instances impacted by the recently remediated critical severity Citrix Bleed information disclosure bug, tracked as CVE-2023-4966, could have their authentication session cookies stolen and be hijacked through a new proof-of-concept exploit discovered by Assetnote researchers, reports BleepingComputer. Analysis of both unpatched and patched NetScaler versions revealed 50 function changes, with two functions using “snprintf”

Source: SC Magazine

 


Date:

Categorie(s):