PT-2005-3959 · Citrix · Citrix Metaframe Presentation Server

Gustavo Gurmandi

·

Published

2005-10-04

·

Updated

2018-08-13

·

CVE-2005-3134

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Citrix Metaframe Presentation Server versions 3.0 through 4.0
Description The issue allows remote attackers to bypass policy restrictions. This can be achieved by downloading the launch.ica file and modifying the ClientName variable, which enables attackers to circumvent existing security policies.
Recommendations For Citrix Metaframe Presentation Server versions 3.0 through 4.0, consider restricting access to the launch.ica file to prevent unauthorized downloads and modifications. As a temporary workaround, restrict changes to the ClientName variable to minimize the risk of policy bypass.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3134

Affected Products

Citrix Metaframe Presentation Server