Coverage › CVE-2023-4966
CVE-2023-4966 Mapped Sigma
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability
- Vendor / product
- Citrix — NetScaler ADC and NetScaler Gateway
- Description (CISA)
- Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
- Added to KEV
- 2023-10-18
- Due date
- 2023-11-08
- Required action
- Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Known
- CWE
- CWE-119
- CISA notes
- https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/, https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
https://nvd.nist.gov/vuln/detail/CVE-2023-4966 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1574 Hijack Execution Flow | exploitation technique | This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens. ref 1 · ref 2 |
live |
| T1005 Data from Local System | primary impact | This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens. ref 1 · ref 2 |
live |
| T1134.001 Token Impersonation/Theft | secondary impact | This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens. ref 1 · ref 2 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1005 Data from Local System primary impact
- DET0380 Detection of Local Data Collection Prior to Exfiltration
AN1070 WindowsAdversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.Tunable:
TargetFilePathRegexParentProcessFilterAN1071 LinuxAdversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.Tunable:TimeWindowScriptToolNameAN1072 macOSAdversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.Tunable:UserContextTargetVolumeAN1073 Network DevicesCollection of device configuration via CLI commands (e.g.,show running-config,copy flash,more), often followed by TFTP/SCP transfers.Tunable:CommandScopeAuthenticatedUserListAN1074 ESXiAdversaries accessing datastore or configuration files viavim-cmd,esxcli, or SCP to extract logs, VMs, or host configurations.Tunable:AccessPathRegexInteractiveShellUsage
Sigma rules tagged attack.t1005 (14)
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=windows category=process_creation · 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks).
This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
Author: Roberto Rodriguez @Cyb3rWard0g
· 2021-10-08 (modified 2023-11-30) · logsource: product=windows category=pipe_created · 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
Detects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database).
Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Author: TropChaud
· 2022-12-19 (modified 2023-01-19) · logsource: product=windows category=process_creation · 24c77512-782b-448a-8950-eddb0785fc71
Detect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
Author: frack113
· 2021-08-16 (modified 2023-05-04) · logsource: product=windows category=process_creation · 2f47f1fd-0901-466e-a770-3b7092834a1b
Detects a command used by conti to dump database
Author: frack113
· 2022-04-08 (modified 2023-01-19) · logsource: product=windows category=process_creation · 4833155a-4053-4c9c-a997-777fcea0baa7
Detect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
Author: Diogo Braz
· 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-04 · logsource: product=windows category=process_creation · 696bfb54-227e-4602-ac5b-30d9d2053312
Detects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
Author: frack113
· 2022-02-13 (modified 2024-03-05) · logsource: product=windows category=process_creation · 6a69f62d-ce75-4b57-8dce-6351eb55b362
One way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
Author: Jason Mull
· 2025-05-12 · logsource: product=windows service=system · 882fbe50-d8d7-4e29-ae80-0648a8556866
Detects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
Author: frack113
· 2021-12-20 (modified 2023-02-13) · logsource: product=windows category=process_creation · b57ba453-b384-4ab9-9f40-1038086b4e53
Detects dump of credentials in VeeamBackup dbo
Author: Austin Clark
· 2019-08-11 (modified 2023-01-04) · logsource: product=cisco service=aaa · cd072b25-a418-4f98-8ebc-5093fb38fe1a
Collect pertinent data from the configuration files
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=linux category=process_creation · f0025a69-e1b7-4dda-a53c-db21fa2d4071
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks).
This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
T1134.001 Token Impersonation/Theft secondary impact
- DET0482 Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
AN1324 WindowsDetection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context.ETW:Token
api_call: DuplicateTokenEx, ImpersonateLoggedOnUser, SetThreadToken→ DC0021 OS API ExecutionTunable:AllowedSystemProcessesTimeWindowUserContextFilterParentProcessAnomalyThreshold
Sigma rules tagged attack.t1134.001 (9)
Author: Michaela Adams, Zach Mathis
· 2022-11-06 (modified 2023-04-26) · logsource: product=windows service=security · 02f7c9c1-1ae8-4c6a-8add-04693807f92f
Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-08 (modified 2023-08-07) · logsource: product=windows category=pipe_created · 0adc67e0-a68f-4ffd-9c43-28905aad5d6a
Detects creation of default named pipes used by the Koh tool
Author: Teymur Kheirkhabarov, Ecco, Florian Roth
· 2019-10-26 (modified 2023-02-05) · logsource: product=windows category=process_creation · 15619216-e993-4721-b590-4c520615a67d
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
Author: Stamatis Chatzimangou (st0pp3r)
· 2024-01-05 · logsource: product=windows service=security · 7b14c76a-c602-4ae6-9717-eff868153fc0
Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators
Author: Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems)
· 2019-10-26 (modified 2023-11-15) · logsource: product=windows service=system · 843544a7-56e0-4dcc-a44f-5cc266dd97d6
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
Author: Nasreddine Bencherchali (Nextron Systems)
· 2024-06-26 · logsource: product=windows category=process_creation · c7d33b50-f690-4b51-8cfb-0fb912a31e57
Detects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata.
SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.
Author: Sai Prashanth Pulisetti @pulisettis
· 2022-12-21 (modified 2024-11-23) · logsource: product=windows category=process_creation · cf0c254b-22f1-4b2b-8221-e137b3c0af94
Detects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
Author: Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems)
· 2019-10-26 (modified 2023-11-15) · logsource: product=windows service=security · ecbc5e16-58e0-4521-9c60-eb9a7ea4ad34
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
Author: Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems)
· 2022-12-27 (modified 2023-02-13) · logsource: product=windows category=process_creation · f89b08d0-77ad-4728-817b-9b16c5a69c7a
Detects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
T1574 Hijack Execution Flow exploitation technique
- DET0218 Detection Strategy for Hijack Execution Flow across OS platforms.
AN0609 WindowsUnusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths.Tunable:
ServiceBaselineAllowedDllPathsTimeWindowAN0610 LinuxAdversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables.auditd:SYSCALLopen/write syscalls targeting /etc/ld.so.preload or binaries in /usr/bin→ DC0061 File ModificationTunable:MonitoredDirectoriesEnvVarMonitorsAN0611 macOSAbuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries.macos:unifiedlogModified application plist or binary replacement in /Applications→ DC0061 File ModificationTunable:AllowedDylibPathsPlistMonitors
Sigma rules tagged attack.t1574 (8)
Author: FPT.EagleEye, Thomas Patzke (improvements)
· 2021-06-29 (modified 2022-06-02) · logsource: product=windows category=image_load · 02fb90de-c321-4e63-a6b9-25f4b03dfd14
Detect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
· 2019-11-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · 1c373b6d-76ce-4553-997d-8c1da9a6b5f5
Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
Author: Florian Roth (Nextron Systems)
· 2019-07-17 (modified 2023-05-24) · logsource: product=windows category=process_creation · 50919691-7302-437f-8e10-1fe088afa145
Detects a "regsvr32" execution where the DLL doesn't contain a common file extension.
Author: Bhabesh Raj
· 2021-07-01 (modified 2023-02-17) · logsource: product=windows category=file_delete · 5b2bbc47-dead-4ef7-8908-0cf73fcbecbf
Detect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
Author: frack113
· 2022-08-07 (modified 2023-08-17) · logsource: product=windows category=registry_set · 9827ae57-3802-418f-994b-d5ecf5cd974b
Detects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
Author: Ivan Dyachkov, Yulia Fomina, oscd.community
· 2020-10-07 (modified 2021-11-27) · logsource: product=windows category=process_creation · a2910908-e86f-4687-aeba-76a5f996e652
Detects using register-cimprovider.exe to execute arbitrary dll file.
Author: Tim Rauch (rule), Elastic (idea)
· 2022-10-21 · logsource: product=windows category=file_event · dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
Author: Florian Roth (Nextron Systems)
· 2020-07-01 (modified 2023-08-17) · logsource: product=windows category=registry_set · e0813366-0407-449a-9869-a2db1119dc41
Detects a suspicious printer driver installation with an empty Manufacturer value
Sigma rules tagged with this CVE directly
4 rules carry cve.2023-4966.
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT)
· 2023-11-28 · logsource: category=webserver · 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
hightest
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-28 · logsource: category=webserver · a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-28 · logsource: category=proxy · aee7681f-b53d-4594-a9de-ac51e6ad3362
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumtest
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT)
· 2023-11-28 · logsource: category=proxy · ff349b81-617f-4af4-924f-dbe8ea9bab41
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.