Citrix Metaframe ICA Client Privilege Inheritance Vulnerability
BID:6641
Info
Citrix Metaframe ICA Client Privilege Inheritance Vulnerability
| Bugtraq ID: | 6641 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2003 12:00AM |
| Updated: | Jan 17 2003 12:00AM |
| Credit: | Vulnerability discovery credited to Steinar Kleven <[email protected]>. |
| Vulnerable: |
Citrix MetaFrame XPe |
| Not Vulnerable: | |
Discussion
Citrix Metaframe ICA Client Privilege Inheritance Vulnerability
Metaframe is a remote desktop software package distributed by Citrix. This issue affects Metaframe on the Microsoft Windows platform.
An alleged problem in Metaframe may have security implications.
This issue is reported to occur when a higher privileged user is prompted with a login dialog for the server holding the print queues and successfully authenticates. The higher privileged users permissions may be transferred to unprivileged ICA client users.
This could result in a violation of security policy. Additionally, this may have unintended consequences across sessions.
Metaframe is a remote desktop software package distributed by Citrix. This issue affects Metaframe on the Microsoft Windows platform.
An alleged problem in Metaframe may have security implications.
This issue is reported to occur when a higher privileged user is prompted with a login dialog for the server holding the print queues and successfully authenticates. The higher privileged users permissions may be transferred to unprivileged ICA client users.
This could result in a violation of security policy. Additionally, this may have unintended consequences across sessions.
Exploit / POC
Citrix Metaframe ICA Client Privilege Inheritance Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Citrix Metaframe ICA Client Privilege Inheritance Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.