In the December 2022 Patch Tuesday, Citrix has fixed a critical zero-day vulnerability in Citrix ADC and Gateway that is actively exploited by state-sponsored hackers (APT5) to gain access to corporate networks.

The fixed vulnerability is a Remote Code Execution issue. The vulnerability only affects the following versions:

  • Citrix ADC and Citrix Gateway 13.0-58.32 and later releases
  • Citrix ADC and Citrix Gateway 12.1-65.25 and later releases of 12.1
  • Citrix ADC 12.1-FIPS 12.1-55.291 and later releases of 12.1-FIPS
  • Citrix ADC 12.1-NDcPP 12.1-55.291 and later releases of 12.1-NDcPP

Our SOC team have analysed the patch in order to confirm its authenticity and relevance to the initial vulnerability.

For in-depth mitigation steps, please refer to our knowledge base article.

This is an ongoing event and we are continuing to track the developments. If you have any questions or need support, please contact our IT service desk on 01904 562207 or email [email protected].