Skip to main content

Citrix Presentation Server and XenApp ActiveSync Remote Code Execution Vulnerability

Last Update Date: 25 Mar 2011 12:18 Release Date: 25 Mar 2011 6809 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Citrix Presentation Server and Citrix XenApp, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the ActiveSync feature when processing malformed packets while synchronizing PDA devices, which could be exploited by remote attackers to crash an affected server or execute arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Citrix Presentation Server version 4.5
  • Citrix XenApp version 5
  • Citrix Access Essentials version 2.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link