Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
BID:48898
Info
Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
| Bugtraq ID: | 48898 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2011 12:00AM |
| Updated: | Jul 26 2011 12:00AM |
| Credit: | n.runs AG Information Security Team |
| Vulnerable: |
Citrix XenDesktop 4 Citrix XenApp Fundamentals 6.0 Citrix XenApp Fundamentals 3.0 Citrix XenApp Fundamentals 2.0 Citrix XenApp 6.0 Citrix XenApp 5.0 Citrix XenApp 4.5 Feature Pack 1 Citrix XenApp 4.5 |
| Not Vulnerable: |
Citrix XenDesktop 5 |
Discussion
Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
Citrix XenApp and XenDesktop are prone to a remote code-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code in the context of a service account on the vulnerable server.
The following products are affected:
XenApp version 6 and prior versions
XenApp Fundamentals version 6 and prior versions
XenDesktop 4
XenDesktop 4 with Feature Packs 1
XenDesktop 4 with Feature Packs 2
Citrix XenApp and XenDesktop are prone to a remote code-execution vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code in the context of a service account on the vulnerable server.
The following products are affected:
XenApp version 6 and prior versions
XenApp Fundamentals version 6 and prior versions
XenDesktop 4
XenDesktop 4 with Feature Packs 1
XenDesktop 4 with Feature Packs 2
Exploit / POC
Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Citrix XenApp and XenDesktop XML Service Interface Remote Code Execution Vulnerability
References:
References: