Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
BID:14989
Info
Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
| Bugtraq ID: | 14989 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2005 12:00AM |
| Updated: | Sep 30 2005 12:00AM |
| Credit: | Gustavo Gurmandi of GrupoITPro Security Research Community discovered this vulnerability. |
| Vulnerable: |
Citrix MetaFrame Presentation Server 4.0 Citrix MetaFrame Presentation Server 3.0 |
| Not Vulnerable: | |
Discussion
Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
Citrix MetaFrame Presentation Server is susceptible to a server policy bypass vulnerability. This issue is due to the application utilizing and trusting client-supplied data in policy decisions.
Attackers may bypass security policies by changing the contents of 'launch.ica' files.
This allows attackers to bypass administratively defined security policies, potentially aiding them in further attacks.
Citrix MetaFrame Presentation Server is susceptible to a server policy bypass vulnerability. This issue is due to the application utilizing and trusting client-supplied data in policy decisions.
Attackers may bypass security policies by changing the contents of 'launch.ica' files.
This allows attackers to bypass administratively defined security policies, potentially aiding them in further attacks.
Exploit / POC
Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
Solution:
The vendor has released document CTX107705 to address this issue. Please see the referenced document for further information.
Solution:
The vendor has released document CTX107705 to address this issue. Please see the referenced document for further information.
References
Citrix MetaFrame Presentation Server Security Policy Bypass Vulnerability
References:
References: