Citrix Provisioning Services StreamProcess.exe Remote Code Execution (CTX130846)

critical Nessus Plugin ID 56392

Synopsis

The remote Windows host has an application running that is affected by a remote code execution vulnerability.

Description

The version of the StreamProcess.exe component included with the Citrix Provisioning Services installation running on the remote Windows host is affected by a remote code execution vulnerability in the Ardence.CMessageUtils.fromMgrString() function in Manager.dll. An unauthenticated, remote attacker can exploit this to execute arbitrary code on the remote host with SYSTEM privileges.

Solution

Apply the relevant patch referenced in the vendor's advisory.

See Also

https://support.citrix.com/article/CTX130846

https://www.zerodayinitiative.com/advisories/ZDI-12-008/

https://www.zerodayinitiative.com/advisories/ZDI-12-009/

https://www.zerodayinitiative.com/advisories/ZDI-12-010/

https://www.zerodayinitiative.com/advisories/ZDI-13-018/

https://www.securityfocus.com/archive/1/521190/30/0/threaded

https://www.securityfocus.com/archive/1/521191/30/0/threaded

https://www.securityfocus.com/archive/1/521193/30/0/threaded

Plugin Details

Severity: Critical

ID: 56392

File Name: citrix_provisioning_services_ctx130846.nasl

Version: 1.18

Type: local

Agent: windows

Family: Windows

Published: 10/5/2011

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/a:citrix:provisioning_services

Required KB Items: SMB/Citrix/Provisioning_Services/Version, SMB/Citrix/Provisioning_Services/Path, SMB/Citrix/Provisioning_Services/StreamProcess.exe

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/27/2011

Vulnerability Publication Date: 9/27/2011

Exploitable With

Metasploit (Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020006 Buffer Overflow)

Reference Information

BID: 49803