'Highly critical' Citrix Presentation Server Client flaw reported

By
Follow google news

A vulnerability in Citrix Presentation Server Client that can be exploited by attackers to compromise a PC was reported this week.


The flaw is caused by an unspecified error within support for ICA connections when using a proxy server, according to an advisory from Secunia. An attacker can exploit the flaw to execute arbitrary code onto a victimised system.

Secunia urged users this week to upgrade to Citrix Presentation Server Client version 10 or later.

The Denmark-based vulnerability monitoring firm ranked the flaw as "highly critical," meaning it can be exploited by a remote user with arbitrary code.

An attacker can exploit the flaw by duping a user into visiting a specially crafted web page, according to an advisory from US-CERT.

Citrix said in an advisory released Tuesday that the flaw is present in versions 9.230 and earlier. Florida based vendor ranked the vulnerability as "high" danger and said that it is "likely to be exploitable in most client deployments."

A Citrix official could not immediately be reached for comment today.

A different flaw in Presentation Server Client was discovered late last year, this one cause by a boundary error within the SendChannelData() method in the ICA Client ActiveX control component that could lead to buffer overflow.

Citrix advised users to upgrade to versions 9.230 to correct that flaw, according to a Secunia advisory.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Australia's critical infrastructure security laws "toothless"

Australia's critical infrastructure security laws "toothless"

"CanisterWorm" supply chain malware attacks npm

"CanisterWorm" supply chain malware attacks npm

Gov proposes disclosure delay for most serious cyberattacks

Gov proposes disclosure delay for most serious cyberattacks

US regulator bans imports of new foreign-made routers

US regulator bans imports of new foreign-made routers

Log In

  |  Forgot your password?