kevmap

Coverage › CVE-2023-4966

CVE-2023-4966 Mapped Sigma

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Vendor / product
Citrix — NetScaler ADC and NetScaler Gateway
Description (CISA)
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
Added to KEV
2023-10-18
Due date
2023-11-08
Required action
Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.
Known ransomware use
Known
CWE
CWE-119
CISA notes
https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/, https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
https://nvd.nist.gov/vuln/detail/CVE-2023-4966
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1574 Hijack Execution Flow exploitation technique This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens.
ref 1 · ref 2
live
T1005 Data from Local System primary impact This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens.
ref 1 · ref 2
live
T1134.001 Token Impersonation/Theft secondary impact This is a buffer overflow vulnerability that results in unauthorized disclosure of memory, including session tokens.
ref 1 · ref 2
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1005 Data from Local System primary impact

Sigma rules tagged attack.t1005 (14)

Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=windows category=process_creation · 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
Author: Roberto Rodriguez @Cyb3rWard0g · 2021-10-08 (modified 2023-11-30) · logsource: product=windows category=pipe_created · 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
Detects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
Techniques: T1005
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Techniques: T1021T1005
Author: TropChaud · 2022-12-19 (modified 2023-01-19) · logsource: product=windows category=process_creation · 24c77512-782b-448a-8950-eddb0785fc71
Detect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
Author: frack113 · 2021-08-16 (modified 2023-05-04) · logsource: product=windows category=process_creation · 2f47f1fd-0901-466e-a770-3b7092834a1b
Detects a command used by conti to dump database
Techniques: T1005
Author: frack113 · 2022-04-08 (modified 2023-01-19) · logsource: product=windows category=process_creation · 4833155a-4053-4c9c-a997-777fcea0baa7
Detect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
Techniques: T1539T1005
Author: Diogo Braz · 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Techniques: T1005T1537
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-04 · logsource: product=windows category=process_creation · 696bfb54-227e-4602-ac5b-30d9d2053312
Detects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
Techniques: T1005
Author: frack113 · 2022-02-13 (modified 2024-03-05) · logsource: product=windows category=process_creation · 6a69f62d-ce75-4b57-8dce-6351eb55b362
One way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
Techniques: T1005
Author: Jason Mull · 2025-05-12 · logsource: product=windows service=system · 882fbe50-d8d7-4e29-ae80-0648a8556866
Detects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
Techniques: T1003.002T1005
Author: frack113 · 2021-12-20 (modified 2023-02-13) · logsource: product=windows category=process_creation · b57ba453-b384-4ab9-9f40-1038086b4e53
Detects dump of credentials in VeeamBackup dbo
Techniques: T1005
Author: Austin Clark · 2019-08-11 (modified 2023-01-04) · logsource: product=cisco service=aaa · cd072b25-a418-4f98-8ebc-5093fb38fe1a
Collect pertinent data from the configuration files
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-24 · logsource: product=linux category=process_creation · efd2eb09-b72e-4a61-8dc7-b1382a1e8983
Detects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
Techniques: T1041T1005
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=linux category=process_creation · f0025a69-e1b7-4dda-a53c-db21fa2d4071
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.

T1134.001 Token Impersonation/Theft secondary impact

Sigma rules tagged attack.t1134.001 (9)

Author: Michaela Adams, Zach Mathis · 2022-11-06 (modified 2023-04-26) · logsource: product=windows service=security · 02f7c9c1-1ae8-4c6a-8add-04693807f92f
Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
Techniques: T1134.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-08 (modified 2023-08-07) · logsource: product=windows category=pipe_created · 0adc67e0-a68f-4ffd-9c43-28905aad5d6a
Detects creation of default named pipes used by the Koh tool
Techniques: T1528T1134.001
Author: Teymur Kheirkhabarov, Ecco, Florian Roth · 2019-10-26 (modified 2023-02-05) · logsource: product=windows category=process_creation · 15619216-e993-4721-b590-4c520615a67d
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
Techniques: T1134.001T1134.002
Author: Stamatis Chatzimangou (st0pp3r) · 2024-01-05 · logsource: product=windows service=security · 7b14c76a-c602-4ae6-9717-eff868153fc0
Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators
Techniques: T1134T1134.001
Author: Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems) · 2019-10-26 (modified 2023-11-15) · logsource: product=windows service=system · 843544a7-56e0-4dcc-a44f-5cc266dd97d6
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
Techniques: T1134.001T1134.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-06-26 · logsource: product=windows category=process_creation · c7d33b50-f690-4b51-8cfb-0fb912a31e57
Detects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata. SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.
Techniques: T1134.001T1134.003
Author: Sai Prashanth Pulisetti @pulisettis · 2022-12-21 (modified 2024-11-23) · logsource: product=windows category=process_creation · cf0c254b-22f1-4b2b-8221-e137b3c0af94
Detects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
Techniques: T1134.001T1134.003
Author: Teymur Kheirkhabarov, Ecco, Florian Roth (Nextron Systems) · 2019-10-26 (modified 2023-11-15) · logsource: product=windows service=security · ecbc5e16-58e0-4521-9c60-eb9a7ea4ad34
Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
Techniques: T1134.001T1134.002
Author: Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems) · 2022-12-27 (modified 2023-02-13) · logsource: product=windows category=process_creation · f89b08d0-77ad-4728-817b-9b16c5a69c7a
Detects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
Techniques: T1134.001T1134.003

T1574 Hijack Execution Flow exploitation technique

Sigma rules tagged attack.t1574 (8)

Author: FPT.EagleEye, Thomas Patzke (improvements) · 2021-06-29 (modified 2022-06-02) · logsource: product=windows category=image_load · 02fb90de-c321-4e63-a6b9-25f4b03dfd14
Detect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
Techniques: T1574
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro · 2019-11-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · 1c373b6d-76ce-4553-997d-8c1da9a6b5f5
Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
CVE tags: CVE-2019-1378
Author: Florian Roth (Nextron Systems) · 2019-07-17 (modified 2023-05-24) · logsource: product=windows category=process_creation · 50919691-7302-437f-8e10-1fe088afa145
Detects a "regsvr32" execution where the DLL doesn't contain a common file extension.
Techniques: T1574
Author: Bhabesh Raj · 2021-07-01 (modified 2023-02-17) · logsource: product=windows category=file_delete · 5b2bbc47-dead-4ef7-8908-0cf73fcbecbf
Detect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
Techniques: T1574
CVE tags: CVE-2021-1675
Author: frack113 · 2022-08-07 (modified 2023-08-17) · logsource: product=windows category=registry_set · 9827ae57-3802-418f-994b-d5ecf5cd974b
Detects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
Techniques: T1574
Author: Ivan Dyachkov, Yulia Fomina, oscd.community · 2020-10-07 (modified 2021-11-27) · logsource: product=windows category=process_creation · a2910908-e86f-4687-aeba-76a5f996e652
Detects using register-cimprovider.exe to execute arbitrary dll file.
Techniques: T1574
Author: Tim Rauch (rule), Elastic (idea) · 2022-10-21 · logsource: product=windows category=file_event · dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
Author: Florian Roth (Nextron Systems) · 2020-07-01 (modified 2023-08-17) · logsource: product=windows category=registry_set · e0813366-0407-449a-9869-a2db1119dc41
Detects a suspicious printer driver installation with an empty Manufacturer value
Techniques: T1574
CVE tags: CVE-2021-1675

Sigma rules tagged with this CVE directly

4 rules carry cve.2023-4966.

Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT) · 2023-11-28 · logsource: category=webserver · 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-28 · logsource: category=webserver · a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-28 · logsource: category=proxy · aee7681f-b53d-4594-a9de-ac51e6ad3362
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT) · 2023-11-28 · logsource: category=proxy · ff349b81-617f-4af4-924f-dbe8ea9bab41
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.
Techniques: T1190
CVE tags: CVE-2023-4966