Citrix Presentation Server 4.5 Code Execution

critical Nessus Plugin ID 69128

Synopsis

The remote host has a virtualization application installed that is affected by a code execution vulnerability.

Description

The version of Citrix Presentation Server installed on the remote Windows host is potentially affected by multiple code execution vulnerabilities. By sending a specially crafted packet to the IMA server process, a remote, unauthenticated attacker could execute arbitrary code subject to the privileges of the user running the IMA server process.

Solution

Apply the patch referenced in the Citrix advisory.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-08-002/

https://support.citrix.com/article/CTX114487

Plugin Details

Severity: Critical

ID: 69128

File Name: citrix_presentation_server_ctx114487.nasl

Version: 1.10

Type: local

Agent: windows

Family: Windows

Published: 7/30/2013

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:citrix:presentation_server

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/17/2008

Vulnerability Publication Date: 1/17/2008

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2008-0356

BID: 27329

CWE: 119

CERT: 412228