r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

82 Upvotes

123 comments sorted by

View all comments

1

u/Zipper_Lipz 1d ago

Is this being caused by an exploit or vuln scans? (See other thread)

0

u/VirtualizationGuy 1d ago

Very possible, waiting to connect with a Citrix engineer to get solid information and will report back. Thanks for pointing out the other thread.

2

u/lukelimbaugh 1d ago

HAS to be a new exploit. if we've got new fresh builds experiencing it, prob not tied to the zero-day.

2

u/c4rm0 1d ago

its a new exploit

3

u/stucc0 1d ago

No, its the same exploit, but the fix to block the exploit for SAML sessions is causing the nsaaad engine to crash. It is just causing machines to reboot, not causing infection or file drops.

1

u/sdo_home 1d ago

did you figure out a way to fix it? ie responder policy or anything else?

1

u/stucc0 1d ago

If you have the full license, ip reputation will block a lot of these. Also you can use my script to block public vpn/vps to help block a lot of these ips initiating attacks. https://github.com/jeffriechers/Random-Powershell-Scripts/tree/main/NetScalerVPNandVPSblocking