Citrix has issued an urgent security update addressing a critical flaw—CVE‑2025‑5777—in its NetScaler ADC and Gateway platforms, now dubbed “Citrix Bleed 2.” The vulnerability, rated CVSS 9.3, poses a significant risk: under certain conditions, threat actors may extract valid authentication tokens from memory, bypassing access controls and potentially gaining unauthorized entry.
The Risk: Tokens Spilled via Malformed Requests
Citrix’s official advisory explains that improper input validation allows malformed traffic to target memory-resident session tokens stored by NetScaler appliances configured as Gateway or AAA virtual servers. With those tokens, attackers could impersonate authenticated users and intrude on corporate environments. While Citrix reports no active exploitation yet, the vulnerability’s mechanics mirror the notorious “Citrix Bleed” incident (CVE‑2023‑4966, CVSS 9.4), making it a prime candidate for weaponization .
Security researcher Kevin Beaumont coined the identifier “Citrix Bleed 2” to highlight parallels to the 2023 leak, noting that the exploitation method and potential impact on session integrity appear remarkably similar.
Affected Versions & Remediation
Citrix has released patches in the following versions:
- ADC and Gateway 14.1‑43.56 and later
- ADC and Gateway 13.1‑58.32 onward
- ADC 13.1‑FIPS/NDcPP 13.1‑37.235 and later
- ADC 12.1‑FIPS 12.1‑55.328 onward
Importantly, the vulnerability also impacts Secure Private Access on-prem and Hybrid deployments that utilize NetScaler. To eliminate active session tokens and thwart token replay, Citrix recommends terminating all ICA and PCoIP sessions post-upgrade using:
bashCopyEditkill icaconnection -all
kill pcoipConnection -all
Older versions—12.1 and 13.0—are End‑of‑Life (EOL) and unsupported, making migration to patched releases critical.
Industry Response: Concern, Preparedness, Precaution
Though no in-the-wild attacks have been disclosed, several security experts say the flaw ticks every box for high-risk vulnerabilities.
Benjamin Harris, CEO of watchTowr, remarked:
“CVE‑2025‑5777 is shaping up to be every bit as serious as Citrix Bleed … the vulnerability is significantly more painful than perhaps first signaled.”
Harris pointed to alterations in the CVE description, which removed references to the flaw being limited to the less-visible Management Interface—suggesting broader exposure and heightened urgency.
SAP GUI Flaws: Local History at Risk
Simultaneously, researchers at Pathlock have unearthed two medium-severity vulnerabilities—CVE‑2025‑0055 and CVE‑2025‑0056 (CVSS 6.0)—affecting the SAP GUI client for Windows and Java . These don’t facilitate remote access, but they expose local user data through weak or absent protections on input history databases.
- SAP GUI for Windows stores history in
%APPDATA%\LocalLow\SAPGUI\Cache\History\SAPHistory<WINUSER>.dbusing a trivial XOR-based “encryption” that can be reversed. - SAP GUI for Java records unencrypted serialized inputs in folders like
%APPDATA%\LocalLow\SAPGUI\Cache\History(Windows/Linux) or~/Library/Preferences/SAP/Cache/History(macOS).
This history may contain sensitive entries—like SSNs, bank details, usernames, or internal SAP configurations—making it easy for anyone with local or administrative access to retrieve them .
Pathlock’s Jonathan Stross highlighted the danger:
“Anyone with access to the computer can potentially access the history file and all sensitive information it stores … exfiltration through HID injection attacks … or phishing becomes a real threat.”
SAP fixed the flaws in its January 2025 monthly update. Users are advised to disable input history and delete existing history files to eliminate residual data.
Recommendations for Enterprises
- Immediate patching: Upgrade NetScaler ADC/Gateway to the respective patched versions (≥12.1‑FIPS 12.1‑55.328, ≥13.1‑58.32, or ≥14.1‑43.56).
- Kill active sessions: Execute Citrix commands to reset ICA and PCoIP sessions after patching.
- Upgrade old systems: Decommission or migrate from EOL versions 12.1/13.0.
- Remove SAP data: Disable SAP input history and purge stored database files.
- Monitor for misuse: Watch logs for abnormal token handling or session anomalies.
Bottom Line
Citrix Bleed 2 is a high-profile vulnerability rooted in input validation lapses, posing an imminent danger of token theft and authenticated intrusions. Its similarities to the 2023 issue underscore its severity and the urgency for patching. Concurrently, SAP GUI’s local history issue reveals the wider threat of complacency—even legacy client features can leak sensitive corporate data.
Together, these discoveries reinforce a critical cybersecurity truth: not all threats originate externally—sometimes the weakest link lies in trusted tools silently logging your secrets.
Please subscribe to the Newsletter so that you do not miss any critical update
