Security Research

CVE-2025-5777 Citrix NetScaler Memory Overread: From <InitialValue> Reflection to Pre-Auth Memory Leak

#Vulnerability Analysis#Code Audit#Cyber Attack
CVE-2025-5777 Citrix NetScaler Memory Overread: From <InitialValue> Reflection to Pre-Auth Memory Leak

Citrix NetScaler reflects the user-supplied login field verbatim into the <InitialValue> tag of the login response XML — the attacker weaponizes this reflection point by sending an oversized login string, which triggers a memory overread in the NetScaler process and returns adjacent memory as part of the response, leaking session tokens, configuration, credentials, and other sensitive data.

Unlock to view this content.