logo

THREAT ALERT: CITRIXBLEED (CVE-2023-4966)

ID: 5dceef0b-c828-5d4a-a804-e2e92c3fe613

STIX ID: report--5dceef0b-c828-5d4a-a804-e2e92c3fe613

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2023-12-18

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason warns of CitrixBleed (CVE-2023-4966), a critical NetScaler ADC/Gateway vulnerability (CVSS 9.4) exploited to cause buffer overreads that leak memory and enable session hijacking and credential theft. The alert documents active post-exploitation activity observed (credential dumping from browsers, MFA bypass, RMM tool deployment, NTDS.DIT retrieval, and custom trojans), provides detection queries and IoCs, and recommends immediate patching, resetting NetScaler sessions, monitoring for unauthorized RMM and unknown DLLs, enabling Cybereason protections, and periodic log review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.