
Citrix has issued crucial security patches for a significant vulnerability (CVE-2024-12284) affecting NetScaler Console and NetScaler Agent. The flaw, rated 8.8 on the CVSS v4 scale, poses a privilege escalation risk through improper privilege management.
The vulnerability specifically impacts authenticated users with existing access to NetScaler Console, allowing potential command execution without proper authorization. While this limits the threat surface to authenticated users only, the security implications remain serious.
Affected Versions:
– NetScaler Console 14.1 (pre 14.1-38.53)
– NetScaler Console 13.1 (pre 13.1-56.18)
– NetScaler Agent 14.1 (pre 14.1-38.53)
– NetScaler Agent 13.1 (pre 13.1-56.18)
Patched Versions:
– NetScaler Console 14.1-38.53 and later
– NetScaler Console 13.1-56.18 and later
– NetScaler Agent 14.1-38.53 and later
– NetScaler Agent 13.1-56.18 and later
Cloud Software Group emphasizes immediate installation of updates, as no alternative workarounds exist. Users of Citrix-managed NetScaler Console Service require no action, as their systems are automatically protected.