Citrix ICA Client Automatic Remote Code Execution Vulnerability
BID:3688
Info
Citrix ICA Client Automatic Remote Code Execution Vulnerability
| Bugtraq ID: | 3688 |
| Class: | Design Error |
| CVE: |
CVE-2001-1192 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered by Michiel Kikkert - [email protected] and posted to the BugTraq mailing list on December 13, 2001. |
| Vulnerable: |
Citrix ICA Client for Windows 6.1 |
| Not Vulnerable: | |
Discussion
Citrix ICA Client Automatic Remote Code Execution Vulnerability
Citrix ICA is a protocol used for remote application serving of terminal based applications.
When the ICA client is installed on a Windows machine, it is associated with the .ICA file extension. Whenever an ICA file is referenced within a web page, the client machine will connect to the published application and execute it, without prompting the user.
Links concealed on pages, for example with hidden frames, could result in arbitrary code being executed on the client machine without the knowledge of the user.
Citrix ICA is a protocol used for remote application serving of terminal based applications.
When the ICA client is installed on a Windows machine, it is associated with the .ICA file extension. Whenever an ICA file is referenced within a web page, the client machine will connect to the published application and execute it, without prompting the user.
Links concealed on pages, for example with hidden frames, could result in arbitrary code being executed on the client machine without the knowledge of the user.
Exploit / POC
Citrix ICA Client Automatic Remote Code Execution Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Citrix ICA Client Automatic Remote Code Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Citrix ICA Client Automatic Remote Code Execution Vulnerability
References:
References:
- Citrix Homepage (Citrix)