Citrix self-hosted products are affected by two flaws: CVE-2023-5914, an unauthenticated reflected cross-site scripting vulnerability in Citrix StoreFront, and CVE-2023-6184, a remote code execution risk in Citrix Session Recording. The StoreFront issue arises from unsanitized exception output in a SAML test endpoint, allowing attacker-controlled XML parsing errors to be reflected in an HTML response.
CVE-2023-6184 affects Citrix Session Recording .NET Remoting SOAP endpoints configured for unrestricted deserialization, a condition that can permit remote code execution. Citrix rated the issue CVSS 5.0 on the basis that default configurations require authentication, but researchers identified internet-exposed instances that could reportedly be exploited without authentication; organizations should identify exposed StoreFront and Session Recording services and apply Citrix security updates and mitigations.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The researchers disclosed both Citrix vulnerabilities to Citrix after their late-2023 discovery.
Researchers discovered the reflected XSS vulnerability CVE-2023-5914 in Citrix StoreFront and the .NET deserialization RCE vulnerability CVE-2023-6184 in Citrix Session Recording in late 2023.
Researchers reported that some internet-exposed Citrix Session Recording instances could be exploited for CVE-2023-6184 without authentication, despite Citrix stating that default configurations require authentication and assigning CVSS 5.0.
Researchers validated code execution through CVE-2023-6184 against a local Citrix Session Recording 2203 installation and confirmed it against a target running version 2308, using exposed .NET Remoting endpoints with unrestricted deserialization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.