Citrix Provisioning Services Remote Code Execution Vulnerability
BID:49803
Info
Citrix Provisioning Services Remote Code Execution Vulnerability
| Bugtraq ID: | 49803 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2011 12:00AM |
| Updated: | Feb 13 2013 12:11PM |
| Credit: | AbdulAziz Hariri of ThirdEyeTesters, and the Zero Day Initiative |
| Vulnerable: |
Citrix Provisioning Services 5.6 SP1 Citrix Provisioning Services 5.6 |
| Not Vulnerable: | |
Discussion
Citrix Provisioning Services Remote Code Execution Vulnerability
Citrix Provisioning Services is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
Citrix Provisioning Services versions 5.6 SP1 and prior are affected.
Citrix Provisioning Services is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
Citrix Provisioning Services versions 5.6 SP1 and prior are affected.
Exploit / POC
Citrix Provisioning Services Remote Code Execution Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Citrix Provisioning Services Remote Code Execution Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
Citrix Provisioning Services Remote Code Execution Vulnerability
References:
References:
- Citrix Homepage (Citrix)
- Vulnerability in Citrix Provisioning Services could result in Arbitrary Code Exe (Citrix)
- ZDI-12-008: Citrix Provisioning Services streamprocess.exe vDisk Name Parsing Re (Zero Day Initiative)
- ZDI-12-009: Citrix Provisioning Services Stream Service 0x40020000 Remote Code E (Zero Day Initiative)
- ZDI-12-010: Citrix Provisioning Services Stream Service 0x40020006 Remote Code E (Zero Day Initiative)