Public exploit code turns NetScaler’s pre-authentication DTLS overflow into root-level execution.
A network caller needs only reachability to a DTLS-enabled Gateway VIP.
Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.
Unauthenticated root-level code execution on a VPN gateway
Version-specific public code converts a reported memory-corruption condition into a reusable unauthenticated root-execution path.
Detail, proof-of-concept code and 5 sources
An unauthenticated caller can complete the DTLS cookie exchange before sending the malicious fragments.
The exploit sends 120 records whose understated fragment lengths make reassembly overflow a smaller scratch buffer with roughly 174 KB of retained data.
Forged objects redirect control flow through a ROP chain and execute shellcode as root; crafted DTLS traffic was also tied to pre-disclosure web-shell activity.
Citrix has shipped a patch, but pre-fix appliance images remain accepted.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
The EOL finding concerns EOL software builds. The reviewed sources do not establish whether every individual EOL hardware platform can run a supported fixed release.