Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
BID:55518
CVE-2012-4603 |Info
Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 55518 |
| Class: | Unknown |
| CVE: |
CVE-2012-4603 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2012 12:00AM |
| Updated: | Sep 12 2012 12:00AM |
| Credit: | Alexey Tyurin of Digital Security Research Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
Citrix Receiver and Citrix Online Plug-in for Windows are prone to an unspecified arbitrary code-execution vulnerability.
An attacker can leverage this issue to execute arbitrary code within the context of the application. Successful exploits will compromise the application and possibly the underlying device.
Citrix Receiver for Windows 3.2 and Citrix Online Plug-in for Windows 12.1; prior versions are also affected.
Citrix Receiver and Citrix Online Plug-in for Windows are prone to an unspecified arbitrary code-execution vulnerability.
An attacker can leverage this issue to execute arbitrary code within the context of the application. Successful exploits will compromise the application and possibly the underlying device.
Citrix Receiver for Windows 3.2 and Citrix Online Plug-in for Windows 12.1; prior versions are also affected.
Exploit / POC
Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
Attackers must entice an unsuspecting user into opening a file on a remote SMB or WebDAV fileserver to exploit this issue.
Attackers must entice an unsuspecting user into opening a file on a remote SMB or WebDAV fileserver to exploit this issue.
Solution / Fix
Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Citrix Receiver and Online Plug-in Unspecified Arbitrary Code Execution Vulnerability
References:
References: