Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
BID:19056
CVE-2006-3779 |Info
Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
| Bugtraq ID: | 19056 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2006 12:00AM |
| Updated: | Jul 19 2006 09:07PM |
| Credit: | The vendor has disclosed this issue. |
| Vulnerable: |
Citrix Presentation Server 4.0 Citrix MetaFrame Presentation Server 3.0 Citrix MetaFrame 1.8 |
| Not Vulnerable: | |
Discussion
Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
Various Citrix applications contain an error that allows an authenticated user to escalate privileges.
The issue occurs because the application fails to prevent malicious attackers from modifying access control lists.
An authenticated user can exploit this issue by crafting malicious DLL file, modifying the original path of the library pointing to the malicious DLL file, and then loading and running the file within the context of the system. This would allow an authenticated user to gain elevated privileges over the metaframe server.
Various Citrix applications contain an error that allows an authenticated user to escalate privileges.
The issue occurs because the application fails to prevent malicious attackers from modifying access control lists.
An authenticated user can exploit this issue by crafting malicious DLL file, modifying the original path of the library pointing to the malicious DLL file, and then loading and running the file within the context of the system. This would allow an authenticated user to gain elevated privileges over the metaframe server.
Exploit / POC
Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
An attacker who is logged into the system can exploit this issue.
An attacker who is logged into the system can exploit this issue.
Solution / Fix
Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please refer to the vendor's homepage for more information.
Citrix MetaFrame 1.8
Citrix MetaFrame Presentation Server 3.0
Solution:
The vendor has released updates to address these issues. Please refer to the vendor's homepage for more information.
Citrix MetaFrame 1.8
-
Citrix Hotfix XE104R02W2K3018 - For MetaFrame XP 1.0 for Windows Server 2003
http://support.citrix.com/hotfixes.jspa?categoryID=120&subCategoryID=1 20&spLevels=&languages=English&productVersion=Citrix%20MetaFrame%20XP% 201.0%20for%20Microsoft%20Windows%202003&productName=MetaFrame%20XP%20 1.0%20for%20Microsoft%20Windows%202003
Citrix MetaFrame Presentation Server 3.0
-
Citrix Hotfix MPSE300R05W2K3006 - For Metaframe Presentation Server 3.0 for Windows Server 2003
http://support.citrix.com/article/CTX110199
References
Various Citrix Applications MFEvent.DLL Privilege Escalation Vulnerabilities
References:
References:
- Citrix Security Advisory (Citrix)