Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
BID:48676
Info
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
| Bugtraq ID: | 48676 |
| Class: | Design Error |
| CVE: |
CVE-2011-2882 CVE-2011-2883 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2011 12:00AM |
| Updated: | Aug 31 2011 07:30AM |
| Credit: | Joshua J. Drake and Michal Trojnara |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
The Citrix Access Gateway Plug-in ActiveX control is prone to multiple remote code-execution vulnerabilities.
Attackers may exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting these issues will allow attackers to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
Citrix Access Gateway Plug-in versions prior to 8.1-67.7, 9.0-70.5, and 9.1-96.4 are vulnerable; other versions may also be affected.
The Citrix Access Gateway Plug-in ActiveX control is prone to multiple remote code-execution vulnerabilities.
Attackers may exploit these issues by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting these issues will allow attackers to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
Citrix Access Gateway Plug-in versions prior to 8.1-67.7, 9.0-70.5, and 9.1-96.4 are vulnerable; other versions may also be affected.
Exploit / POC
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Citrix Access Gateway Plug-in ActiveX Control Multiple Code Execution Vulnerabilities
References:
References: