CVE-2023-3519
ID: d4a4b655-edad-552a-8a12-328775752cda
STIX ID: report--d4a4b655-edad-552a-8a12-328775752cda
Feed Name: Zscaler Security Research Blog
### Executive summary The report describes active exploitation of Citrix Gateway CVE-2023-3519 in which attackers upload TGZ archives containing web shells and setuid binaries to obtain unauthenticated RCE, escalate privileges, decrypt ADC-stored configuration keys to extract Active Directory credentials, perform network discovery, compress and encrypt harvested data for exfiltration, and evade detection by hiding artifacts and disguising exfiltrated files as images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
