Skip to content

ndr-repo/CVE-2025-5777

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

Exploit for CVE-2025-5777: Citrix NetScaler Memory Disclosure (CitrixBleed 2) [T1606]

Description

  • External, unauthenticated exploit for memory leak in Citrix NetScaler Gateway & AAA Virtual Server
  • Leverages insufficient input validation in the web app to fire the payload, and TOCTOU Race Conditions to scrape variables in memory

Asset Discovery & Exposure Analysis - (Red/Purple Team -> Organization)

Method 1: Search Engine Dorking

site:<targetDomainSuffix> intitle:"Netscaler AAA" | intitle:"Citrix Gateway"

Method 2: Hunter.how

domain.suffix=="<targetDomainSuffix>" and header.server="snow_adc"

Exploit Usage

bash CVE-2025-5777.sh <targetDomain>

Pivoting - Red Team Operations

Objective - Pivot externally without credentials -> internal with low priv user credentials over VPN

Methodology

  • Inspect response bodies and experiment with decoding and escaping to gain visibility on the asset - log files, etc.
  • Inspect response headers, repeat til capture of active user session cookies in memory - Demonstration by horizon3.ai
  • Authenticate to the target domain

References

About

Exploit for CVE-2025-5777: Citrix NetScaler Memory Disclosure (CitrixBleed 2)

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages