PT-2008-5889 · Citrix · Citrix Xenapp+3
Publicado
2008-10-22
·
Atualizado
2017-08-08
·
CVE-2008-4676
CVSS v2.0
6.8
Média
| Vetor | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Citrix XenApp versions 4.5 Feature Pack 1 and earlier
Citrix Presentation Server version 4.0
Citrix Access Essentials versions 1.0, 1.5, and 2.0
Description
The issue allows local users to gain privileges via unknown attack vectors related to creating an unspecified file.
Recommendations
For Citrix XenApp versions 4.5 Feature Pack 1 and earlier, consider restricting access to file creation functionality until a patch is available.
For Citrix Presentation Server version 4.0, restrict access to file creation functionality to minimize the risk of exploitation.
For Citrix Access Essentials versions 1.0, 1.5, and 2.0, avoid using file creation features in sensitive environments until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Access Essentials
Citrix Metaframe Presentation Server
Citrix Presentation Server
Citrix Xenapp