<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ADC - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/adc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 29 Jan 2024 10:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/adc/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Citrix ADC CVE-2023-3519 Exploitation Attempts</title><link>https://feed.craftedsignal.io/briefs/2024-01-citrix-adc-cve-2023-3519/</link><pubDate>Mon, 29 Jan 2024 10:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2024-01-citrix-adc-cve-2023-3519/</guid><description>Exploitation attempts against Citrix ADC via CVE-2023-3519, a SAML processing overflow, detected through specific POST requests, could lead to arbitrary code execution, privilege escalation, or service disruption.</description><content:encoded><![CDATA[<p>This threat brief focuses on potential exploitation attempts targeting Citrix ADC (Application Delivery Controller) instances vulnerable to CVE-2023-3519. This vulnerability is a SAML processing overflow issue that can lead to memory corruption. Publicly disclosed in July 2023, CVE-2023-3519 allows unauthenticated attackers to perform arbitrary code execution on affected systems. Observed exploitation includes POST requests to specific web endpoints indicative of attempts to trigger this vulnerability. Successful exploitation could allow attackers to gain a foothold within the targeted network, leading to further malicious activities. This activity is significant because it involves a critical vulnerability in a widely used application delivery controller.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies a vulnerable Citrix ADC instance exposed to the internet.</li>
<li>The attacker sends a crafted POST request to one of the following vulnerable endpoints: <code>/cgi/logout</code>, <code>*/saml/activelogin</code>, <code>*/saml/login</code>, <code>/cgi/samlart?samlart=*</code>, <code>/cgi/samlauth</code>, <code>/gwtest/formssso?event=start&amp;target=*</code>, or <code>/netscaler/ns_gui/vpn/*</code>.</li>
<li>The crafted POST request exploits the SAML processing overflow vulnerability (CVE-2023-3519) to corrupt memory.</li>
<li>The memory corruption leads to arbitrary code execution within the Citrix ADC appliance.</li>
<li>The attacker leverages the code execution to establish a persistent foothold on the system, potentially installing a web shell.</li>
<li>The attacker escalates privileges to gain administrative control over the Citrix ADC.</li>
<li>The attacker uses the compromised Citrix ADC as a pivot point to move laterally within the internal network.</li>
<li>The attacker exfiltrates sensitive data, deploys ransomware, or causes disruption to critical services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2023-3519 can have severe consequences, including arbitrary code execution, privilege escalation, and complete system compromise. This can lead to data breaches, service disruptions, and financial losses. The vulnerability affects Citrix ADC and Citrix Gateway, which are widely used in various sectors. The &quot;X-Force Uncovers Global NetScaler Gateway Credential Harvesting Campaign&quot; reference indicates this vulnerability has been actively exploited in credential harvesting campaigns.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rules in this brief to your SIEM to detect potential exploitation attempts against Citrix ADC instances.</li>
<li>Apply the patches provided by Citrix for CVE-2023-3519 as detailed in the Citrix security bulletin (<a href="https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)">https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467)</a>.</li>
<li>Review web server logs for POST requests to the vulnerable endpoints listed in the attack chain to identify potential exploitation attempts.</li>
<li>Ensure that the Web datamodel is populated from a supported Technology Add-On in Splunk as mentioned in the &quot;how_to_implement&quot; section.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>citrix</category><category>cve-2023-3519</category><category>saml</category><category>exploitation</category></item></channel></rss>