1.0 Introduction
Citrix released security updates to address multiple vulnerabilities in NetScaler ADC, NetScaler Gateway, and Citrix Session Recording.
2.0 Impact
A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system.
3.0 Affected Products
- NetScaler ADC and NetScaler Gateway 14.1 – before version 14.1-29.72
- NetScaler ADC and NetScaler Gateway 13.1 – before version 13.1-55.34
- NetScaler ADC 13.1-FIPS – before version 13.1-37.207
- NetScaler ADC 12.1-FIPS – before version 12.1-55.321
- NetScaler ADC 12.1-NDcPP – before version 12.1-55.321
- Citrix Virtual Apps and Desktops before 2407 hotfix 24.5.200.8
- Citrix Virtual Apps and Desktops 1912 LTSR before CU9 hotfix 19.12.9100.6
- Citrix Virtual Apps and Desktops 2203 LTSR before CU5 hotfix 22.03.5100.11
- Citrix Virtual Apps and Desktops 2402 LTSR before CU1 hotfix 24.02.1200.16
4.0 Recommendations
CyberSecurity Malaysia encourages users and administrators to review the
Citrix Security Bulletin
and apply the necessary updates.
Kindly refer to the following URL for more information:
- NetScaler ADC and NetScaler Gateway: https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US
- Citrix Session Recording: https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US
Generally, we advise users of these devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact us through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 08:30 -17:30 MYT
Web:
https://www.mycert.org.my
5.0 References
- https://www.cisa.gov/news-events/alerts/2024/11/12/citrix-releases-security-updates-netscaler-and-citrix-session-recording
- https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US
- https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US