黑客利用 CitrixBleed 2 劫持会话令牌并绕过企业 MFA 防护

CitrixBleed 2 CVE-2025-5777 session hijacking NetScaler vulnerability MFA bypass
J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 
2026年7月18日
3 分钟阅读
黑客利用 CitrixBleed 2 劫持会话令牌并绕过企业 MFA 防护

TL;DR

• 严重的 CVE-2025-5777 漏洞允许攻击者绕过企业 MFA 防护。 • 黑客通过未经授权的会话令牌劫持攻击 NetScaler ADC/Gateway。 • 全球已有超过 100 家组织被入侵,数千个实例仍未打补丁。 • 该漏洞的 CVSS 评分为 9.3,需要立即修复。 • 攻击者利用输入验证不足来冒充合法用户。

黑客利用 CitrixBleed 2 劫持会话令牌并绕过企业 MFA 防护

安全领域目前正受到“CitrixBleed 2”的严重冲击,该漏洞被追踪为 CVE-2025-5777。这不仅仅是一个理论上的漏洞;它正被积极利用以攻破企业 NetScaler 基础设施。从本质上讲,这是一个越界内存读取漏洞。通俗地说,它允许未经身份验证的攻击者窃取敏感内存、劫持活动用户会话,并直接绕过企业的多因素身份验证 (MFA)。

这不是一种隐蔽的攻击手段,而是一种强力手段。通过向 /p/u/doAuthentication.do 端点发送单个精心构造的 HTTP POST 请求,攻击者可以有效地冒充合法用户。由于它直接针对身份验证处理程序,它已成为威胁行为者在企业网络中建立立足点的首选方式。一旦进入,他们往往就能掌握核心权限。

攻击规模

其后果已经非常严重。报告证实,至少有 100 家组织已通过 CitrixBleed 2 被入侵。更糟糕的是:尽管有紧急警告和可用的补丁,全球仍有数千个 Citrix 实例处于未打补丁的暴露状态。

CISA 已知被利用漏洞 (KEV) 目录 于 2025 年 7 月 10 日正式标记了此漏洞,这足以说明其危险程度。该漏洞的 CVSS 评分为 9.3,属于“必须立即停止一切工作进行修复”的级别。其根本原因是 NetScaler ADC 和 Gateway 身份验证过程中存在典型的输入验证不足问题(具体为 CWE-457)。

黑客利用 CitrixBleed 2 劫持会话令牌并绕过企业 MFA 防护

图片来源:Splunk Blog

技术原理:为何有效

该漏洞对 NetScaler ADC 和 Gateway 设备造成了严重打击,特别是那些充当 VPN、ICA、CVPN、RDP 或 AAA 虚拟服务器的设备。通过操纵身份验证处理程序,攻击者既不需要你的密码,也不需要你的 MFA 令牌。他们已经绕过了守门人。

深入分析 CitrixBleed 2 攻击机制 可以发现,内存泄漏提供了足够多的会话数据来克隆合法用户的身份。这种攻击精准、快速且极具破坏力。

属性 详情
漏洞 ID CVE-2025-5777
CVSS 评分 9.3 (严重)
根本原因 输入验证不足 (CWE-457)
攻击向量 未经身份验证的 HTTP POST
主要端点 /p/u/doAuthentication.do

如何加固系统

如果你正在运行 NetScaler 基础设施,你没有时间等待。你需要立即核实补丁状态。Citrix 的官方指南 是你的修复路线图。

以下是你需要立即采取的行动:

  • 全面打补丁: 不要只修复边缘设备;在所有 NetScaler ADC 和 Gateway 实例上安装最新的供应商更新。
  • 仔细检查日志: 查找针对 /p/u/doAuthentication.do 端点的可疑 HTTP POST 请求。如果发现此类请求,请假设你已被入侵。
  • 收紧边界: 如果无法立即打补丁,请将管理和身份验证接口的访问权限限制为仅限受信任的 IP 范围。这只是权宜之计,但总比敞开大门要好。
  • 警惕异常会话: 密切关注异常的会话活动或与用户习惯不符的并发登录。

该威胁的持续存在是因为互联网上仍有大量未打补丁的设备。由于该漏洞易于执行且回报(完全会话劫持)极高,它目前是网络犯罪分子的首要目标。

现实情况是,在每个易受攻击的实例修复之前,风险始终处于极高水平。如果你还没有核实你的环境,请将此视为警钟。请将 CVE-2025-5777 视为对你内部网络完整性的严重威胁。不要等到收到警报才发现被攻击——现在就采取主动措施来保护你的基础设施。

J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 

James Okoro is a certified ethical hacker (CEH) and cybersecurity journalist with a background in military intelligence. After serving as a cyber operations analyst, he transitioned into the private sector, working as a threat intelligence consultant before finding his voice as a writer. James has covered major data breaches, ransomware campaigns, and state-sponsored cyberattacks for several leading security publications. He brings a tactical, insider perspective to his reporting on the ever-evolving threat landscape.

相关新闻

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000 zero-day

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances face active exploitation by UTA0533. CVE-2026-15409 and CVE-2026-15410 allow root access. Patch your systems immediately.

作者: James Okoro 2026年7月21日 4 分钟阅读
common.read_full_article
Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security
WireGuard VPN protocol

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security

Private Internet Access integrates WireGuard protocol across its suite for faster, more secure remote access. Learn how this update improves your VPN connection.

作者: Marcus Chen 2026年7月20日 4 分钟阅读
common.read_full_article
Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks
CVE-2023-4966

Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks

Discover how the Citrix Bleed (CVE-2023-4966) vulnerability allows session hijacking. Learn how to patch your NetScaler Gateway against authentication bypass.

作者: Elena Voss 2026年7月19日 4 分钟阅读
common.read_full_article
New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats
shadow IT

New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats

Discover why shadow IT and remote infrastructure are critical enterprise security threats. Learn how to secure your decentralized network against modern attacks.

作者: Marcus Chen 2026年7月17日 5 分钟阅读
common.read_full_article