Article Details
Scrape Timestamp (UTC): 2025-02-20 04:45:04.315
Source: https://thehackernews.com/2025/02/citrix-releases-security-fix-for.html
Original Article Text
Click to Toggle View
Citrix Releases Security Fix for NetScaler Console Privilege Escalation Vulnerability. Citrix has released security updates for a high-severity security flaw impacting NetScaler Console (formerly NetScaler ADM) and NetScaler Agent that could lead to privilege escalation under certain conditions. The vulnerability, tracked as CVE-2024-12284, has been given a CVSS v4 score of 8.8 out of a maximum of 10.0 It has been described as a case of improper privilege management that could result in authenticated privilege escalation if the NetScaler Console Agent is deployed and allows an attacker to execute post-compromise actions. "The issue arises due to inadequate privilege management and could be exploited by an authenticated malicious actor to execute commands without additional authorization," Netscaler noted. "However, only authenticated users with existing access to the NetScaler Console can exploit this vulnerability, thereby limiting the threat surface to only authenticated users." The shortcoming affects the below versions - It has been remediated in the below versions of the software - "Cloud Software Group strongly urges customers of NetScaler Console and NetScaler Agent to install the relevant updated versions as soon as possible," the company said, adding there are no workarounds to resolve the flaw. That said, customers who are using Citrix-managed NetScaler Console Service do not need to take any action.
Daily Brief Summary
Citrix has released updates to address a high-severity vulnerability in NetScaler Console and NetScaler Agent.
The flaw, identified as CVE-2024-12284, scores 8.8 on the CVSS v4 scale and involves improper privilege management.
This security issue allows authenticated users to escalate privileges if they have access to the NetScaler Console.
The vulnerability is limited to users with existing console access, reducing the potential threat surface.
Affected versions of the software have been identified, and security patches are now available.
Citrix urges all NetScaler Console and Agent users to install these security updates immediately to mitigate risk.
No action is required for users of the Citrix-managed NetScaler Console Service regarding this specific vulnerability.