CVE-2025-7775

9.8 CISA KEV

Citrix · NetScaler ADC and NetScaler Gateway

A memory overflow vulnerability in NetScaler ADC and NetScaler Gateway allows unauthenticated attackers to achieve remote code execution or cause a denial of service.

Executive summary

This critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway is currently being actively exploited in the wild, posing an immediate risk of remote code execution.

Vulnerability

The flaw is a memory buffer overflow (CWE-119) that occurs when NetScaler is configured as a Gateway or AAA virtual server. This vulnerability can be triggered by an unauthenticated attacker, allowing for remote code execution or service disruption.

Business impact

The CVSS score of 9.8 reflects the critical nature of this flaw, as it allows full system compromise without requiring authentication. Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the underlying service, potentially leading to total loss of confidentiality, integrity, and availability. Given the product's role as a network gateway, compromise could facilitate widespread unauthorized access to the internal network.

Remediation

Immediate Action: Update affected NetScaler ADC and Gateway instances to the versions specified in the vendor advisory (CTX694938), specifically 14.1-47.48, 13.1-59.22, 13.1-37.241, or 12.1-55.330 and their respective later releases.

Proactive Monitoring: Review system and application logs for unusual traffic patterns, unexpected process crashes, or unauthorized outbound connections originating from the NetScaler appliance.

Compensating Controls: If immediate patching is not feasible, restrict access to the affected Gateway or AAA virtual server interfaces by enforcing strict source IP filtering at the network perimeter.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub repositories.

Analyst recommendation

Due to the critical severity, the presence of active exploitation, and the availability of public exploit code, organizations must treat this vulnerability as a top priority. Administrators should apply the vendor-provided patches immediately to all exposed NetScaler instances. Failure to remediate this vulnerability significantly increases the risk of a successful breach and subsequent lateral movement within the environment.

More Citrix CVEs

Sources