{"id":32813,"date":"2020-01-16T23:13:09","date_gmt":"2020-01-16T23:13:09","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/"},"modified":"2020-01-16T23:13:09","modified_gmt":"2020-01-16T23:13:09","slug":"bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/","title":{"rendered":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#8217;t work for older kit"},"content":{"rendered":"<p><strong class=\"trailer\">Vid<\/strong> Easy-to-use exploits have emerged online for two high-profile security vulnerabilities, namely the Windows certificate spoofing bug and the Citrix VPN gateway hole. If you haven&#8217;t taken mitigation steps by now, you&#8217;re about to have a bad time.<\/p>\n<p>While IT admins can use the proof-of-concept exploit code to check their own systems are secure, miscreants can use them to, in the case of Citrix, hijack remote systems, or in the case of Windows, masquerade malware as legit apps or potentially intercept encrypted web traffic. Patches are available from Microsoft for the Windows vulnerability and should be deployed as soon as possible.<\/p>\n<p>For Citrix, it will not be fully patched until January 20, and in the meantime, in certain cases, the official mitigations are not sufficient to thwart all methods of exploitation. There are an estimated 120,000 or more potentially vulnerable boxen on the open internet.<\/p>\n<h3 class=\"crosshead\"><span>Windows smashed<\/span><\/h3>\n<p>Within hours of the NSA going <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2020\/01\/14\/patch_tuesday_january_2020\/\" rel=\"noopener noreferrer\">public with details<\/a> about its prized bug find, exploit writers posted working code demonstrating how the flaw can be abused to trick unpatched Windows computers into accepting fake digital certificates \u2013 which are used to verify the legitimacy of software, and encrypt web connections.<\/p>\n<p>The vulnerability, <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-0601\">CVE-2020-0601<\/a>, lies within the crypt32.dll library in Windows 10 as well as Server 2016 and 2019. For what it&#8217;s worth, the bug occurs when matching an attacker-supplied certificate to a cached trusted cert held in an internal data structure. It&#8217;s a logic flaw \u2013 the attacker&#8217;s cert is matched without fully validating it \u2013 rather than a mathematical weakness.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2020\/01\/14\/shutterstock_2020_vr.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"A man wearing a VR headset in the year 2020\"><\/p>\n<h2 title=\"Grab your Microsoft, Adobe, SAP, Intel, and VMware fixes now\">Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows cert-spoofing bugs, RDP flaws&#8230;<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2020\/01\/14\/patch_tuesday_january_2020\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>One proof-of-concept code sample available to all is a tiny package of just <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/github.com\/kudelskisecurity\/chainoffools\">50-or-so lines of Python<\/a>. Despite the ease with which the exploit is able to do its work, the author, Yolan Romailler at Swiss security shop Kudelski, said people shouldn&#8217;t panic over the network traffic eavesdropping aspect of CVE-2020-0601: a snoop has to be able to intercept your connections.<\/p>\n<p>&#8220;In the end, please keep in mind that such a vulnerability is not at risk of being exploited by script kiddies or ransomware,&#8221; <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/research.kudelskisecurity.com\/2020\/01\/15\/cve-2020-0601-the-chainoffools-attack-explained-with-poc\/\">notes<\/a> Romailler in his detailed write-up of the bug.<\/p>\n<p>&#8220;While it is still a big problem because it could have allowed a man-in-the-middle attack against any website, you would need to face an adversary that owns the network on which you operate, which is possible for nation-state adversaries, but less so for a script kiddie.<\/p>\n<p>&#8220;This is also probably why the NSA decided not to weaponize their finding, but to rather disclose it: for them it is best to have the USA patched rather than to keep it and take the risk of it being used against the USA, as the attack surface is so vast.&#8221;<\/p>\n<p>As for the nitty-gritty of the bug, Romailler summarized it thus:<\/p>\n<p>Meanwhile, infosec outfit Trail of Bits has dubbed the flaw Whose Curve Is It Anyway? along with <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/whosecurve.com\/\">a logo and website<\/a>, which features a proof-of-concept attack, as is customary these days. The biz succinctly summed up the bug thus:<\/p>\n<p>There&#8217;s more technical info <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/blog.trailofbits.com\/2020\/01\/16\/exploiting-the-windows-cryptoapi-vulnerability\/\">here<\/a>. And you can find another proof-of-concept exploit <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/twitter.com\/ollypwn\/status\/1217819776560574466\">here<\/a> with a signed and unsigned 7z.exe file as an example.<\/p>\n<h3 class=\"crosshead\"><span>Cit-tricked<\/span><\/h3>\n<p>Things are less straightforward when it comes to the other major security bug dominating the news in the past week. The <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2019\/12\/23\/patch_now_published_citrix_applications_leave_network_vulnerable_to_unauthorised_access\/\" rel=\"noopener noreferrer\">Citrix VPN gateway bug<\/a> CVE-2019-19781, dubbed Shitrix by the infosec community, is under active exploit in the wild. Worse yet, Citrix has <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/support.citrix.com\/article\/CTX267027\">admitted<\/a> that, for some installations running older firmware, its recommended mitigation techniques are not holding up against exploits. If you&#8217;re using Citrix ADC Release 12.1 builds before 51.16\/51.19 and 50.31, you should try to upgrade your version.<\/p>\n<p>Better yet, you should configure your network monitoring to catch attempts to exploit the software. A SANS ISC video describing the security snafu is below.<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=msslpqyf98c\" data-media=\"x-videoplayer\">Youtube Video<\/a><\/p>\n<p><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.ncsc.nl\/actueel\/nieuws\/2020\/januari\/16\/door-citrix-geadviseerde-mitigerende-maatregelen-niet-altijd-effectief\">An alert<\/a> from the Dutch National Cyber Security Centre advises organizations that run Citrix ADC and Gateway boxes to consider turning off the machines entirely until the full-scale patch from Citrix is released on January 20.<\/p>\n<p>&#8220;If the impact of switching off the Citrix ADC and Gateway servers is not acceptable, the advice is to closely monitor for possible abuse,&#8221; a translation of the alert reads. &#8220;As a last risk-limiting measure you can still look at whitelisting of specific IP addresses or IP blocks.&#8221;<\/p>\n<p>As for exploits, you can find one proof-of-concept sample <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/github.com\/trustedsec\/cve-2019-19781\">here<\/a>. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1889\/-8120\/detecting-cyber-attacks-as-a-small-to-medium-business?td=wptl1889\">Detecting cyber attacks as a small to medium business<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/go.theregister.co.uk\/feed\/www.theregister.co.uk\/2020\/01\/16\/windows_citrix_patch_update\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Good news: There is none. Well, apart from you can at least fully patch the Microsoft blunder Vid\u00a0 Easy-to-use exploits have emerged online for two high-profile security vulnerabilities, namely the Windows certificate spoofing bug and the Citrix VPN gateway hole. If you haven&#8217;t taken mitigation steps by now, you&#8217;re about to have a bad time.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":32814,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-32813","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#039;t work for older kit 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#039;t work for older kit 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-16T23:13:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#8217;t work for older kit\",\"datePublished\":\"2020-01-16T23:13:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/\"},\"wordCount\":779,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/\",\"name\":\"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg\",\"datePublished\":\"2020-01-16T23:13:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/01\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#8217;t work for older kit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/","og_locale":"en_US","og_type":"article","og_title":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-01-16T23:13:09+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#8217;t work for older kit","datePublished":"2020-01-16T23:13:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/"},"wordCount":779,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/","url":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/","name":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don't work for older kit 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg","datePublished":"2020-01-16T23:13:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/01\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/bad-news-windows-security-cert-snafu-exploits-are-all-over-the-web-now-also-bad-citrix-gateway-hole-mitigations-dont-work-for-older-kit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Bad news: Windows security cert SNAFU exploits are all over the web now. Also bad: Citrix gateway hole mitigations don&#8217;t work for older kit"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/32813","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=32813"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/32813\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/32814"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=32813"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=32813"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=32813"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}