Citrix speeds up patches for exploited Netscaler vulnerability

By
Follow google news

First fixes released.

Digital workspace provider Citrix now expects to deliver patches for the serious remote code execution vulnerability in its Netscaler Application Delivery Controller product by January 25 Australian time.

Citrix speeds up patches for exploited Netscaler vulnerability

The company has already released patches for Citrix ADC and Gateway versions 11.1 and 12.0. 

To install the security fixes, version 11.1 Netscaler ADC and Gateway instances have to be upgraded to build 11.1.63.15, and 12.0 instances to 12.0.63.13, Citrix said.

Likewise, the forthcoming updates for Citrix Netscaler ADC and Gateway versions 10.5, 12.1 and 13.0 as well as the SD-WAN WANOP product release 10.2.6 and 11.0.3 all need to be upgraded with refresh builds before patches can be installed.

While there are mitigation measures available to prevent attackers from exploiting the CVE-2019-19781 flaw that was disclosed on December 17 United States time, Citrix urged its customers to immediately install the fixes.

Furthermore, the mitigation measures are not effective on system version 12.1.50.28.

Attackers are currently scanning the internet for vulnerable Citrix devices to compromise, installing crypto currency miners and other malware.

In one instance, security reserchers found malware being planted on Citrix devices that deletes malicious code already deployed on them, and then applies mitigations to prevent further exploitation while retaining remote access via a cryptographically secured backdoor.

 

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

Log In

  |  Forgot your password?