Citrix Presentation Server and XenApp ActiveSync Remote Code Execution Vulnerability
RISK: High Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Citrix Presentation Server and Citrix XenApp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the ActiveSync feature when processing malformed packets while synchronizing PDA devices, which could be exploited by remote attackers to crash an affected server or execute arbitrary code.
Impact
- Remote Code Execution
System / Technologies affected
- Citrix Presentation Server version 4.5
- Citrix XenApp version 5
- Citrix Access Essentials version 2.0
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply patches :
http://support.citrix.com/article/CTX128366
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with