駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

CitrixBleed 2 CVE-2025-5777 session hijacking NetScaler vulnerability MFA bypass
J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 
2026年7月18日
3 分鐘閱讀
駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

TL;DR

• 嚴重的 CVE-2025-5777 漏洞允許攻擊者繞過企業 MFA 防護。 • 駭客透過未經授權的工作階段權杖劫持,鎖定 NetScaler ADC/Gateway。 • 全球已有超過 100 個組織受害,數千個實例仍未修補。 • 該漏洞 CVSS 評分為 9.3,需立即進行修復。 • 攻擊者利用輸入驗證不足來冒充合法使用者。

駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

資安界目前正因「CitrixBleed 2」而陷入動盪,該漏洞被追蹤為 CVE-2025-5777。這不僅僅是另一個理論上的漏洞,它正被積極利用來入侵企業的 NetScaler 基礎設施。其核心問題在於記憶體越界讀取(out-of-bounds memory read)缺陷。簡單來說,它允許未經身份驗證的攻擊者竊取敏感記憶體資料、劫持活躍的使用者工作階段,並直接繞過多因素身份驗證(MFA),彷彿防護機制不存在一樣。

這並非隱蔽的攻擊手法,而是一種強力的破壞手段。攻擊者只需向 /p/u/doAuthentication.do 端點發送一個特製的 HTTP POST 請求,即可有效地冒充合法使用者。由於它直接針對身份驗證處理程序,這已成為威脅行為者在企業網路中建立據點的首選手段。一旦進入,他們便能長驅直入,甚至掌握企業網路的最高權限。

入侵規模

目前造成的影響已經相當顯著。報告證實,至少已有 100 個組織透過 CitrixBleed 2 遭到入侵。更令人擔憂的是,儘管已有緊急警告和修補程式,全球仍有數千個 Citrix 實例處於未修補的門戶大開狀態。

CISA 已知利用漏洞 (KEV) 目錄 於 2025 年 7 月 10 日正式標記此漏洞,這足以說明其危險程度。其 CVSS 評分為 9.3,屬於「必須立即放下手邊工作進行修復」的等級。其根本原因是 NetScaler ADC 和 Gateway 身份驗證過程中存在輸入驗證不足(CWE-457)的問題。

駭客利用 CitrixBleed 2 劫持工作階段權杖並繞過企業 MFA 防護

圖片來源:Splunk Blog

技術剖析:為何此漏洞有效

該漏洞對 NetScaler ADC 和 Gateway 設備造成嚴重打擊,特別是那些作為 VPN、ICA、CVPN、RDP 或 AAA 虛擬伺服器的設備。透過操縱身份驗證處理程序,攻擊者不需要您的密碼,更不需要您的 MFA 權杖,因為他們已經繞過了守門人。

若深入探討,CitrixBleed 2 攻擊機制的技術分析顯示,記憶體洩漏提供了足夠的工作階段資料來複製合法使用者的身份。這種攻擊精確、快速且極具破壞力。

屬性 詳細資訊
漏洞 ID CVE-2025-5777
CVSS 評分 9.3 (嚴重)
根本原因 輸入驗證不足 (CWE-457)
攻擊向量 未經身份驗證的 HTTP POST
主要端點 /p/u/doAuthentication.do

如何加強防護

如果您正在運行 NetScaler 基礎設施,您沒有等待的餘地,必須立即確認修補狀態。Citrix 官方指南是您的修復藍圖。

您需要立即採取以下行動:

  • 全面修補: 不要只修補邊緣設備;請在所有 NetScaler ADC 和 Gateway 實例上安裝最新的廠商更新。
  • 檢查日誌: 搜尋是否有針對 /p/u/doAuthentication.do 端點的可疑 HTTP POST 請求。如果發現此類請求,請假設您已遭到入侵。
  • 收緊邊界: 如果無法立即修補,請將管理和身份驗證介面的存取權限限制在受信任的 IP 範圍內。這雖然只是臨時措施,但總比門戶大開要好。
  • 監控異常工作階段: 密切注意異常的工作階段活動或與使用者習慣不符的並發登入情況。

此威脅的持續存在,是因為網路上仍有大量未修補的設備。由於該漏洞執行容易且回報豐厚(完全的工作階段劫持),它目前是網路犯罪分子的首要目標。

現實情況是,在每個易受攻擊的實例修補完成之前,風險始終極高。如果您尚未驗證您的環境,請將此視為警鐘。請將 CVE-2025-5777 視為對您內部網路完整性的嚴重威脅。不要等到收到警報才發現自己已受害,請立即採取主動措施來保護您的基礎設施。

J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 

James Okoro is a certified ethical hacker (CEH) and cybersecurity journalist with a background in military intelligence. After serving as a cyber operations analyst, he transitioned into the private sector, working as a threat intelligence consultant before finding his voice as a writer. James has covered major data breaches, ransomware campaigns, and state-sponsored cyberattacks for several leading security publications. He brings a tactical, insider perspective to his reporting on the ever-evolving threat landscape.

相關新聞

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks
OpenVPN vulnerabilities

Outdated OpenVPN Implementations Expose Commercial VPN Clients to Critical Vulnerabilities and Security Risks

A 2026 security audit reveals many commercial VPNs use outdated, vulnerable OpenVPN versions. See which providers are leaving your data exposed to RCE attacks.

作者: James Okoro 2026年8月5日 4 分鐘閱讀
common.read_full_article
SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure
SonicWall VPN vulnerabilities

SonicWall VPN Vulnerabilities and AI-Powered Hacking Campaigns Pose New Risks to Enterprise Infrastructure

Hackers are exploiting SonicWall VPNs via CVE-2024-40766 and credential stuffing. Learn how to secure your enterprise infrastructure against these attacks.

作者: Viktor Sokolov 2026年8月4日 4 分鐘閱讀
common.read_full_article
Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack
npm supply chain attack

Amazon Threat Intelligence Links North Korean Hackers to Malicious npm Supply Chain Attack

Amazon threat intelligence links North Korean hackers to malicious npm supply chain attacks. Discover how popular libraries like axios were weaponized.

作者: Elena Voss 2026年8月3日 4 分鐘閱讀
common.read_full_article
AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks
AWS threat intelligence

AWS Threat Intelligence Report Links North Korean Hackers to Open-Source Supply Chain Attacks

AWS threat report reveals North Korean hackers are poisoning open-source repositories to infiltrate cloud environments and harvest developer credentials.

作者: James Okoro 2026年8月2日 5 分鐘閱讀
common.read_full_article