Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Citrix NetScaler ADC and Gateway Memory Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A memory overflow vulnerability has been identified in Citrix NetScaler ADC and NetScaler Gateway. This vulnerability can cause unpredictable or erroneous behavior, leading to a denial-of-service condition. It occurs when NetScaler is configured as a Gateway with a PCoIP Profile bound to it.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, disrupting normal service operations.

Reproduction

To reproduce this vulnerability, NetScaler must be configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with a PCoIP Profile bound to it. This can be verified by inspecting the NetScaler configuration for the presence of a VPN virtual server with the PCoIP profile.

Remediation

Affected customers should upgrade to NetScaler ADC and NetScaler Gateway versions 14.1-47.48 or later, 13.1-59.22 or later, or for versions 12.1-FIPS and 12.1-NDcPP, to 12.1-55.330 and later. NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End Of Life and no longer supported.

Added: Aug 26, 2025, 1:20 PM
Updated: Aug 26, 2025, 1:47 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
9.3
remediation
8.3
relevance
0.4
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.