logo

CVE-2023-3519

ID: d4a4b655-edad-552a-8a12-328775752cda

STIX ID: report--d4a4b655-edad-552a-8a12-328775752cda

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

### Executive summary The report describes active exploitation of Citrix Gateway CVE-2023-3519 in which attackers upload TGZ archives containing web shells and setuid binaries to obtain unauthenticated RCE, escalate privileges, decrypt ADC-stored configuration keys to extract Active Directory credentials, perform network discovery, compress and encrypt harvested data for exfiltration, and evade detection by hiding artifacts and disguising exfiltrated files as images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.