1 min read
Critical Vulnerabilities in Microsoft and Fortinet Products
Published 04/13/2023 I. Targeted Entities Windows and Fortinet systems II. Introduction Several critical vulnerabilities were discovered in both...
6 min read
Cyber Florida SOCAP Team
:
Updated on August 14, 2026
Published 11/13/2023
This cyberattack has been targeting NetScaler application delivery controller (ADC) and NetScaler Gateway; tools that improve the delivery speed of applications to an end user and provide secure remote access to applications and services, respectively. Threat actors exploited this vulnerability as a zero-day attack to drop a webshell. The webshell allowed the threat actors to access the victim’s Active Directory (AD) and collect and exfiltrate data.
In June 2023, threat actors exploited a public-facing application called NetScaler Application Delivery Controller and NetScaler Gateway. Threat actors implanted a webshell on the organization’s NetScaler ADC appliance and then abused elevation controls to initiate an exploit chain to a binary file to extract data.
The affected versions for Netscaler and Netscaler Gateway following this vulnerability are 13.1 and earlier, up to 13.1-40.13. Initially, CVE-2023-3519 was CVE-2019-19781, which was discovered in December 2019 and attracted significant attention due to its potential to be exploited for the same purpose as it is being observed (unauthenticated remote code execution). In the 2019-29781 CVE, attackers would gain access through the Citrix NetScaler server to exploit public-facing applications such as Citrix ADC and gateway, and we can see that happening in the 2023-3519 CVE as well.
According to NIST’s CVSS Severity and Metrics, the vulnerability has been rated as follows:
Threat Actor Activity
Victim 1
As part of their initial exploit chain [T1190], the threat actors uploaded a TGZ file [T1105] containing a generic webshell [T1505.003], discovery script [TA0007], and setuid binary [T1548.001] on the ADC appliance and conducted SMB scanning on the subnet [T1046].
Threat Actor Activity
Victim 2
Threat actors uploaded a PHP webshell *logouttm.php* [T1036.005], likely as part of their initial exploit chain, to */netscaler/ns_gui/vpn/. Within an hour of installing the webshell, the actors implanted an Executable and Linkable Format (ELF) binary pykeygen that set the user's unique identifier (UID) to root and executed /bin/sh [T1059.004] via setuid and execve syscall.* [T1106]. Note: A third party also observed threat actors use an ELF binary (named pip4) to execute /bin/sh via syscall and change the UID to root. pip4 was located at /var/python/bin.
With root-level access, the actors used a hands-on keyboard for discovery. They queried the AD via ldapsearch for users, groups, and computers. They collected the data in gzipped text files, renamed 1.css and 2.css, and placed the files in /netscaler/ns_gui/vpn/ for exfiltration.
After exfiltrating the files, the actors deleted them from the system [T1070.004], as well as some access, error, and authentication logs [T1070.002]. The victim organization detected the intrusion and mitigated the activity, but did not identify any additional malicious activity.
For command-and-control (C2), the actors appeared to use compromised pfSense devices [T1584]; the victim observed communications with two pfSense IP addresses, indicating the actors were using them for multi-hop proxying of C2 traffic [T1090.003].
Updated vulnerabilities affecting Netscaler ADC and Netscaler Gateway:
As of October 23rd, Cyber Florida received updates regarding vulnerabilities affecting Netscaler ADC and Netscaler Gateway. The vulnerabilities mentioned: CVE-2023-4966 and CVE 2023-4967 both place high in the CVSS score for severity, and should be mitigated immediately. CVE-2023-4966, a sensitive information disclosure vulnerability, allows attackers to get access to large amounts of data in memory at the end of a buffer. Frequently seen in this attack vector are efforts to obtain unauthenticated access to previous session tokens, allowing attackers to impersonate authenticated users and escalate privileges. CVE 2023-4967, although less critical than the first observed vulnerability, is still a severe vulnerability that can lead to a Denial of Service (D.O.S) attack and cause great harm to a company.
As of October 23rd, updated effective versions of Netscaler ADC and Netscaler Gateway are the following:
IOC’s Affiliated with Citrix CVE-2023-3519 Exploitation
Third-party provides IP addresses affiliated with Citrix CVE-2023-3519
Third-party provided IOCs affiliated with Citrix CVE-2023-3519
Updated NetScaler ADC and NetScaler Gateway containing unauthenticated buffer-related vulnerabilities *10/23/2023*
Threat actors exploiting Citrix CVE-2023-3519 to Implant Webshells – CISA. https://www.cisa.gov/sites/default/files/2023-07/aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf
Enterprise Techniques. Mitre ATT&CK®. (n.d.). https://attack.mitre.org/versions/v13/techniques
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-4966 and CVE-2023-4967. (2023, October 23). https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
Rapid. (n.d.). CVE-2023-4966: Exploitation of Citrix NetScaler Information Disclosure Vulnerability. Rapid7. https://www.rapid7.com/blog/post/2023/10/25/etr-cve-2023-4966-exploitation-of-citrix-netscaler-information-disclosure-vulnerability/#:~:text=On%20October%2010%2C%202023%2C%20Citrix,the%20end%20of%20a%20buffer.
Contributing Security Analysts: EJ Bulut, Nahyan Jamil, Alessandro Lovadina, Ben Price, Erika Delvalle, Ariana Manrique, Yousef Blassy
1 min read
Published 04/13/2023 I. Targeted Entities Windows and Fortinet systems II. Introduction Several critical vulnerabilities were discovered in both...
1 min read
Originally Published March 4, 2025
1 min read
Originally published: 06/16/2022 I. Targeted Entities Microsoft Office users II. Introduction Microsoft has recently established a workaround for a...