黑客利用 CitrixBleed 2 劫持會話令牌並繞過企業 MFA 保護

CitrixBleed 2 CVE-2025-5777 session hijacking NetScaler vulnerability MFA bypass
J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 
2026年7月18日
3 分鐘閱讀
黑客利用 CitrixBleed 2 劫持會話令牌並繞過企業 MFA 保護

TL;DR

• 嚴重的 CVE-2025-5777 漏洞允許攻擊者繞過企業 MFA 保護。 • 黑客透過未經授權的會話令牌劫持,針對 NetScaler ADC/Gateway 進行攻擊。 • 全球已有超過 100 個組織受害,仍有數千個實例未修補。 • 該漏洞的 CVSS 評分為 9.3,需要立即修復。 • 攻擊者利用輸入驗證不足來冒充合法用戶。

黑客利用 CitrixBleed 2 劫持會話令牌並繞過企業 MFA 保護

安全界目前正因「CitrixBleed 2」而陷入恐慌,該漏洞被追蹤為 CVE-2025-5777。這不僅僅是另一個理論上的漏洞;它正被積極武器化,以突破企業的 NetScaler 基礎設施。其核心是一個越界記憶體讀取缺陷。簡單來說,它允許未經身份驗證的攻擊者竊取敏感記憶體、劫持活動用戶會話,並繞過多重身份驗證 (MFA),就好像它根本不存在一樣。

這不是一個隱蔽的攻擊,而是一次重擊。透過向 /p/u/doAuthentication.do 端點發送單個精心構造的 HTTP POST 請求,攻擊者可以有效地冒充合法用戶。由於它直接針對身份驗證處理程序,因此它已成為威脅行為者在企業網絡中建立立足點的首選手段。一旦他們進入,他們就掌握了核心權限。

入侵規模

影響已經相當嚴重。報告證實,至少有 100 個組織已透過 CitrixBleed 2 被入侵。更糟糕的是,儘管有緊急警告和可用的修補程式,仍有數千個 Citrix 實例處於未修補的開放狀態。

CISA 已知被利用漏洞 (KEV) 目錄 於 2025 年 7 月 10 日正式標記了此漏洞,這足以說明其危險程度。該漏洞的 CVSS 評分為 9.3,屬於「放下一切立即修復」的級別。根本原因是 NetScaler ADC 和 Gateway 身份驗證過程中存在經典的輸入驗證不足問題——具體為 CWE-457。

黑客利用 CitrixBleed 2 劫持會話令牌並繞過企業 MFA 保護

圖片來源:Splunk Blog

技術分析:為何它有效

該漏洞對 NetScaler ADC 和 Gateway 設備造成了嚴重打擊,特別是那些作為 VPN、ICA、CVPN、RDP 或 AAA 虛擬伺服器的設備。透過操縱身份驗證處理程序,攻擊者不需要您的密碼,更不需要您的 MFA 令牌。他們已經繞過了守門人。

如果您想深入了解,CitrixBleed 2 攻擊機制的技術分析顯示,記憶體洩漏提供了足夠的會話數據來複製合法用戶的身份。這種攻擊精確、快速且極具破壞力。

屬性 詳細資訊
漏洞 ID CVE-2025-5777
CVSS 評分 9.3 (嚴重)
根本原因 輸入驗證不足 (CWE-457)
攻擊向量 未經身份驗證的 HTTP POST
主要端點 /p/u/doAuthentication.do

如何加強防禦

如果您正在運行 NetScaler 基礎設施,您沒有時間等待。您需要立即驗證您的修補狀態。Citrix 的官方指南是您的修復路線圖。

您需要立即採取以下行動:

  • 全面修補: 不要只修補邊緣設備;請在所有 NetScaler ADC 和 Gateway 實例上安裝最新的供應商更新。
  • 檢查日誌: 尋找針對 /p/u/doAuthentication.do 端點的可疑 HTTP POST 請求。如果發現此類請求,請假設您已被入侵。
  • 收緊邊界: 如果無法立即修補,請將管理和身份驗證介面的存取權限限制為僅限受信任的 IP 範圍。這是一個臨時的補救措施,但總比門戶大開要好。
  • 留意異常會話: 密切關注異常的會話活動或與用戶習慣不符的並發登入。

此威脅的持續存在是因為網路上仍有大量未修補的設備。由於該漏洞易於執行且回報豐厚(完全的會話劫持),它目前是網絡犯罪分子的首要目標。

現實情況是,在每個易受攻擊的實例修補之前,風險仍然極高。如果您尚未驗證您的環境,請將此視為警鐘。請將 CVE-2025-5777 視為對您內部網絡完整性的嚴重威脅。不要等到收到警報才發現被攻擊——現在就主動採取行動保護您的基礎設施。

J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 

James Okoro is a certified ethical hacker (CEH) and cybersecurity journalist with a background in military intelligence. After serving as a cyber operations analyst, he transitioned into the private sector, working as a threat intelligence consultant before finding his voice as a writer. James has covered major data breaches, ransomware campaigns, and state-sponsored cyberattacks for several leading security publications. He brings a tactical, insider perspective to his reporting on the ever-evolving threat landscape.

相關新聞

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000 zero-day

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances face active exploitation by UTA0533. CVE-2026-15409 and CVE-2026-15410 allow root access. Patch your systems immediately.

作者: James Okoro 2026年7月21日 4 分鐘閱讀
common.read_full_article
Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security
WireGuard VPN protocol

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security

Private Internet Access integrates WireGuard protocol across its suite for faster, more secure remote access. Learn how this update improves your VPN connection.

作者: Marcus Chen 2026年7月20日 4 分鐘閱讀
common.read_full_article
Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks
CVE-2023-4966

Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks

Discover how the Citrix Bleed (CVE-2023-4966) vulnerability allows session hijacking. Learn how to patch your NetScaler Gateway against authentication bypass.

作者: Elena Voss 2026年7月19日 4 分鐘閱讀
common.read_full_article
New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats
shadow IT

New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats

Discover why shadow IT and remote infrastructure are critical enterprise security threats. Learn how to secure your decentralized network against modern attacks.

作者: Marcus Chen 2026年7月17日 5 分鐘閱讀
common.read_full_article