Description

Citrix has rolled out a series of security patches to address several recently discovered flaws affecting its range of products. One of the most severe issues, cataloged as CVE-2025-5777, involves an out-of-bounds memory access vulnerability resulting from inadequate input handling. This flaw specifically threatens environments where NetScaler is used to support remote access features such as VPN gateways, ICA proxy, CVPN, RDP Proxy or when configured as an AAA virtual server for authentication and authorization. The security updates are included in NetScaler ADC builds such as 14.1-43.56, 13.1-58.32, and various certified editions including those under FIPS and NDcPP compliance. Updates were also delivered for NetScaler Gateway in corresponding versions to mitigate the same critical vulnerability. In addition to this major issue, Citrix also resolved CVE-2025-5349, a high-severity problem related to flawed access restrictions in the management interface that could allow unauthorized users to manipulate system components. Two more vulnerabilities involving privilege escalation on Windows platforms were addressed as well. The first, CVE-2025-0320, was found in the Secure Access Client for Windows and allowed attackers to obtain system-level permissions. Citrix fixed this flaw in version 25.5.1.15. The second, CVE-2025-4879, targeted the Citrix Workspace app for Windows. Patches were made available in the 2409 release and also in updates for long-term support versions 2402 LTSR CU2 Hotfix 1 and CU3 Hotfix 1. Citrix also reminded customers that older versions of NetScaler specifically 12.1 and 13.0 are still vulnerable but are no longer supported, as they’ve reached the end of their maintenance lifecycle. Organizations relying on these outdated versions are strongly advised to upgrade to supported builds without delay. Although no active exploitation has been detected in the wild, users are urged to apply the latest updates promptly to reduce the risk of future attacks.