Citrix released security updates for NetScaler Console and NetScaler Agent to fix CVE-2024-12284, a high-severity flaw with a CVSS score of 8.8. The vulnerability stems from improper privilege management and could let an authenticated attacker with access to a vulnerable system escalate privileges and execute commands remotely. Citrix published the issue through its support bulletin and a NetScaler security update, while national defenders including CSIRT.SK warned that organizations running local deployments should treat the issue as urgent.
Affected releases include NetScaler Console and NetScaler Agent 14.1 versions earlier than 14.1-38.53 and 13.1 versions earlier than 13.1-56.18. Citrix said its managed solutions had already been secured, but customer-managed instances require patching and hardening. Organizations were advised to upgrade immediately to 13.1-56.18, 14.1-38.53, or later, and to follow NetScaler Console secure-deployment best practices to reduce exposure.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Citrix stated that Citrix-managed solutions were already secured against CVE-2024-12284, while customer-managed instances still required patching. The advisory recommended upgrading affected 13.1 and 14.1 versions to fixed releases and following hardening guidance.
Citrix issued security updates for NetScaler Console and NetScaler Agent to remediate CVE-2024-12284, a high-severity improper privilege management flaw with CVSS 8.8. The vulnerability could let an authenticated attacker escalate privileges and execute commands remotely on vulnerable systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcenetscaler.com
Open sourcesupport.citrix.com
Open sourcedocs.netscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.