All stories
criticalRansomwareCVE-2025-5777

Ransomware actors exploit Citrix vulnerabilities and Bring Your Own Vulnerable Driver techniques

Summary

A critical vulnerability in NetScaler ADC, identified as CVE-2025-5777, has been actively exploited by threat actors linked to ransomware operations. The flaw stems from insufficient input validation that allows for a memory overread condition. This occurs when the NetScaler device is configured with specific virtual server types, including VPN Gateways, ICA Proxies, CVPNs, RDP Proxies, or AAA virtual servers.

The vulnerability carries a CVSS score of 9.3, reflecting its high impact on confidentiality, integrity, and availability. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog as of July 10, 2025, confirming that attackers are successfully using this flaw in the wild to target organizations.

Technical details

The core of CVE-2025-5777 is a memory overread vulnerability triggered by inadequate input validation within the NetScaler ADC software. When an attacker sends specifically crafted requests to a vulnerable instance, they can force the system to read beyond intended memory boundaries.

This technical flaw becomes exploitable under specific configuration scenarios. The risk is present if the NetScaler is acting as a Gateway-specifically for VPN virtual servers, ICA Proxies, CVPN, or RDP Proxy functions-or if it is configured as an AAA (Authentication, Authorization, and Accounting) virtual server. Because the vulnerability can be triggered remotely without authentication, it provides a direct path for attackers to interact with the system memory.

Exploitation status

This vulnerability is not merely theoretical; it is currently being leveraged by ransomware-linked actors. CISA's inclusion of CVE-2025-5777 in its KEV catalog highlights that exploitation is ongoing and widespread.

The high CVSS score of 9.3 underscores the severity of the threat, as the vulnerability allows for significant impact across multiple security pillars. Attackers can use this memory overread to potentially leak sensitive information or facilitate further stages of an attack against the underlying infrastructure.

Defender guidance

Organizations running NetScaler ADC must prioritize patching their appliances. The primary defense is to apply the official updates provided by the vendor to remediate the insufficient input validation flaw.

If immediate patching is not possible, defenders should audit their current configurations to identify all active Gateway and AAA virtual servers. Monitor these specific services for unusual traffic patterns or unexpected memory errors that could indicate an exploitation attempt. Because this vulnerability targets critical entry points like VPN and RDP proxies, securing these paths is essential to preventing unauthorized network access.

For detailed technical documentation and official remediation steps, refer to the vendor's advisory: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420

Sources

  1. https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
  2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -