駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

CitrixBleed 2 CVE-2025-5777 session hijacking NetScaler vulnerability MFA bypass
J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 
2026年7月18日
3 分鐘閱讀
駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

TL;DR

• 嚴重的 CVE-2025-5777 漏洞允許攻擊者繞過企業 MFA 防護。 • 駭客透過未經授權的工作階段權杖劫持,鎖定 NetScaler ADC/Gateway。 • 全球已有超過 100 個組織受害,數千個實例仍未修補。 • 該漏洞 CVSS 評分為 9.3,需立即進行修復。 • 攻擊者利用輸入驗證不足來冒充合法使用者。

駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

資安界目前正因「CitrixBleed 2」而陷入動盪,該漏洞被追蹤為 CVE-2025-5777。這不僅僅是另一個理論上的漏洞,它正被積極利用來入侵企業的 NetScaler 基礎設施。其核心問題在於記憶體越界讀取(out-of-bounds memory read)缺陷。簡單來說,它允許未經身份驗證的攻擊者竊取敏感記憶體資料、劫持活躍的使用者工作階段,並直接繞過多因素身份驗證(MFA),彷彿防護機制不存在一樣。

這並非隱蔽的攻擊手法,而是一種強力的破壞手段。攻擊者只需向 /p/u/doAuthentication.do 端點發送一個特製的 HTTP POST 請求,即可有效地冒充合法使用者。由於它直接針對身份驗證處理程序,這已成為威脅行為者在企業網路中建立據點的首選手段。一旦進入,他們便能長驅直入,甚至掌握企業網路的最高權限。

入侵規模

目前造成的影響已經相當顯著。報告證實,至少已有 100 個組織透過 CitrixBleed 2 遭到入侵。更令人擔憂的是,儘管已有緊急警告和修補程式,全球仍有數千個 Citrix 實例處於未修補的門戶大開狀態。

CISA 已知利用漏洞 (KEV) 目錄 於 2025 年 7 月 10 日正式標記此漏洞,這足以說明其危險程度。其 CVSS 評分為 9.3,屬於「必須立即放下手邊工作進行修復」的等級。其根本原因是 NetScaler ADC 和 Gateway 身份驗證過程中存在輸入驗證不足(CWE-457)的問題。

駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

圖片來源:Splunk Blog

技術剖析:為何此漏洞有效

該漏洞對 NetScaler ADC 和 Gateway 設備造成嚴重打擊,特別是那些作為 VPN、ICA、CVPN、RDP 或 AAA 虛擬伺服器的設備。透過操縱身份驗證處理程序,攻擊者不需要您的密碼,更不需要您的 MFA 權杖,因為他們已經繞過了守門人。

若深入探討,CitrixBleed 2 攻擊機制的技術分析顯示,記憶體洩漏提供了足夠的工作階段資料來複製合法使用者的身份。這種攻擊精確、快速且極具破壞力。

屬性 詳細資訊
漏洞 ID CVE-2025-5777
CVSS 評分 9.3 (嚴重)
根本原因 輸入驗證不足 (CWE-457)
攻擊向量 未經身份驗證的 HTTP POST
主要端點 /p/u/doAuthentication.do

如何加強防護

如果您正在運行 NetScaler 基礎設施,您沒有等待的餘地,必須立即確認修補狀態。Citrix 官方指南是您的修復藍圖。

您需要立即採取以下行動:

  • 全面修補: 不要只修補邊緣設備;請在所有 NetScaler ADC 和 Gateway 實例上安裝最新的廠商更新。
  • 檢查日誌: 搜尋是否有針對 /p/u/doAuthentication.do 端點的可疑 HTTP POST 請求。如果發現此類請求,請假設您已遭到入侵。
  • 收緊邊界: 如果無法立即修補,請將管理和身份驗證介面的存取權限限制在受信任的 IP 範圍內。這雖然只是臨時措施,但總比門戶大開要好。
  • 監控異常工作階段: 密切注意異常的工作階段活動或與使用者習慣不符的並發登入情況。

此威脅的持續存在,是因為網路上仍有大量未修補的設備。由於該漏洞執行容易且回報豐厚(完全的工作階段劫持),它目前是網路犯罪分子的首要目標。

現實情況是,在每個易受攻擊的實例修補完成之前,風險始終極高。如果您尚未驗證您的環境,請將此視為警鐘。請將 CVE-2025-5777 視為對您內部網路完整性的嚴重威脅。不要等到收到警報才發現自己已受害,請立即採取主動措施來保護您的基礎設施。

J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 

James Okoro is a certified ethical hacker (CEH) and cybersecurity journalist with a background in military intelligence. After serving as a cyber operations analyst, he transitioned into the private sector, working as a threat intelligence consultant before finding his voice as a writer. James has covered major data breaches, ransomware campaigns, and state-sponsored cyberattacks for several leading security publications. He brings a tactical, insider perspective to his reporting on the ever-evolving threat landscape.

相關新聞

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000 zero-day

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances face active exploitation by UTA0533. CVE-2026-15409 and CVE-2026-15410 allow root access. Patch your systems immediately.

作者: James Okoro 2026年7月21日 4 分鐘閱讀
common.read_full_article
Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security
WireGuard VPN protocol

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security

Private Internet Access integrates WireGuard protocol across its suite for faster, more secure remote access. Learn how this update improves your VPN connection.

作者: Marcus Chen 2026年7月20日 4 分鐘閱讀
common.read_full_article
Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks
CVE-2023-4966

Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks

Discover how the Citrix Bleed (CVE-2023-4966) vulnerability allows session hijacking. Learn how to patch your NetScaler Gateway against authentication bypass.

作者: Elena Voss 2026年7月19日 4 分鐘閱讀
common.read_full_article
New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats
shadow IT

New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats

Discover why shadow IT and remote infrastructure are critical enterprise security threats. Learn how to secure your decentralized network against modern attacks.

作者: Marcus Chen 2026年7月17日 5 分鐘閱讀
common.read_full_article