PT-2005-3959 · Citrix · Citrix Metaframe Presentation Server
Gustavo Gurmandi
·
Published
2005-10-04
·
Updated
2018-08-13
·
CVE-2005-3134
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Citrix Metaframe Presentation Server versions 3.0 through 4.0
Description
The issue allows remote attackers to bypass policy restrictions. This can be achieved by downloading the launch.ica file and modifying the
ClientName variable, which enables attackers to circumvent existing security policies.Recommendations
For Citrix Metaframe Presentation Server versions 3.0 through 4.0, consider restricting access to the launch.ica file to prevent unauthorized downloads and modifications. As a temporary workaround, restrict changes to the
ClientName variable to minimize the risk of policy bypass.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Citrix Metaframe Presentation Server