Citrix EPA ActiveX Control Design Flaw
BID:24865
Info
Citrix EPA ActiveX Control Design Flaw
| Bugtraq ID: | 24865 |
| Class: | Design Error |
| CVE: |
CVE-2007-3679 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2007 12:00AM |
| Updated: | Jul 23 2007 11:36PM |
| Credit: | Michael White is credited with the discovery of this vulnerability. |
| Vulnerable: |
Citrix Access Gateway Standard Edition 4.5 Citrix Access Gateway Advanced Edition 4.5 Citrix Access Gateway AAC 4.0 Citrix Access Gateway AAC 4.2 Citrix Access Gateway 0 |
| Not Vulnerable: | |
Discussion
Citrix EPA ActiveX Control Design Flaw
Citrix EPA ActiveX control is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into visiting a malicious webpage.
Successful exploits may allow attackers to execute arbitrary code on a victim's computer. This may facilitate a compromise of vulnerable computers.
Citrix EPA ActiveX control is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into visiting a malicious webpage.
Successful exploits may allow attackers to execute arbitrary code on a victim's computer. This may facilitate a compromise of vulnerable computers.
Exploit / POC
Citrix EPA ActiveX Control Design Flaw
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
Solution / Fix
Citrix EPA ActiveX Control Design Flaw
Solution:
The vendor released a fix to address this issue. Please see the references for more information.
Solution:
The vendor released a fix to address this issue. Please see the references for more information.
References
Citrix EPA ActiveX Control Design Flaw
References:
References:
- Citrix Homepage (Citrix)
- Citrix Product Update (Citrix)
- SYMSA-2007-006: Citrix EPA ActiveX Control Design Flaw (Symantec)