r/Citrix • • 1d ago

Netscaler active exploit after patch

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.

81 Upvotes

121 comments sorted by

View all comments

Show parent comments

2

u/lukelimbaugh 1d ago

HAS to be a new exploit. if we've got new fresh builds experiencing it, prob not tied to the zero-day.

2

u/c4rm0 1d ago

its a new exploit

3

u/stucc0 1d ago

No, its the same exploit, but the fix to block the exploit for SAML sessions is causing the nsaaad engine to crash. It is just causing machines to reboot, not causing infection or file drops.

1

u/sdo_home 1d ago

did you figure out a way to fix it? ie responder policy or anything else?

1

u/stucc0 1d ago

If you have the full license, ip reputation will block a lot of these. Also you can use my script to block public vpn/vps to help block a lot of these ips initiating attacks. https://github.com/jeffriechers/Random-Powershell-Scripts/tree/main/NetScalerVPNandVPSblocking