← Back to Feed
MAR-10478915-1.v1 Citrix Bleed
CVE-2023-4966
November 21, 2023 · CISA Advisories · Severity: CRITICAL
CISA received four files for analysis in response to the Citrix Bleed vulnerability (CVE-2023-4966) affecting NetScaler ADC and Gateway appliances. The files include a Windows batch file, executable, DLL, and Python script used to save registry hives, dump LSASS memory, and establish WinRM sessions. This activity is associated with LockBit 3.0 ransomware affiliates.
Key Takeaways
- Files analyzed include a batch file, executable, DLL, and Python script from Citrix Bleed exploitation.
- The files save registry hives, dump LSASS process memory, and attempt WinRM sessions.
- CISA received these files in response to CVE-2023-4966 affecting Citrix NetScaler appliances.