PT-2025-25651 · Citrix · Citrix Netscaler Adc +1
Jdoe
+1
·
Published
2025-06-17
·
Updated
2025-07-17
·
CVE-2025-5777
10
Critical
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Citrix NetScaler ADC and Gateway versions prior to 14.1-29.72
Citrix NetScaler ADC and Gateway versions prior to 13.1-58.32
**Description:**
Citrix NetScaler ADC and Gateway are affected by an out-of-bounds read vulnerability due to insufficient input validation. This allows unauthenticated remote attackers to potentially leak sensitive information, including session tokens, and hijack user sessions. Exploitation of this vulnerability, dubbed "CitrixBleed 2" (CVE-2025-5777), has been observed in the wild, with active exploitation attempts detected prior to the public release of a proof-of-concept exploit. The vulnerability is particularly critical when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Over 1,200 systems have been identified as potentially vulnerable.
**Recommendations:**
Citrix NetScaler ADC and Gateway versions prior to 14.1-29.72: Upgrade to version 14.1-29.72 or later.
Citrix NetScaler ADC and Gateway versions prior to 13.1-58.32: Upgrade to version 13.1-58.32 or later.
Terminate all ICA and PCoIP sessions after patching to prevent hijacked sessions from persisting.
Exploit
Fix
DoS
Out of bounds Read
Use of Uninitialized Resource
Related Identifiers
Affected Products
References · 382
- 🔥 https://github.com/win3zz/CVE-2025-5777⭐ 9 · Exploit
- https://bdu.fstec.ru/vul/2025-07142 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-5777 · Security Note
- https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420 · Security Note, Vendor Advisory
- https://twitter.com/xcybersecnews/status/1943689255085109327 · Twitter Post
- https://twitter.com/cybertzar/status/1937375547945844820 · Twitter Post
- https://twitter.com/wvipersg/status/1935601916794335449 · Twitter Post
- https://t.me/c/1129491012/128387 · Telegram Post
- https://twitter.com/transilienceai/status/1939913037802348695 · Twitter Post
- https://t.me/c/1322172467/1168 · Telegram Post
- https://twitter.com/vpnlabel/status/1944293138677547492 · Twitter Post
- https://twitter.com/CyberSecuriUS/status/1944575713690177909 · Twitter Post
- https://twitter.com/Strivehawk/status/1942560283123187841 · Twitter Post
- https://twitter.com/DCICyberSecNews/status/1944771006490407311 · Twitter Post
- https://twitter.com/pigram86/status/1943542834235072757 · Twitter Post