vendor:
Presentation Server Client
by:
Andrew Christensen, Aaron Portnoy, e.b.
9.3
CVSS
HIGH
Heap Buffer Overflow
119
CWE
Product Name: Presentation Server Client
Affected Version From: 9.200.44376.0
Affected Version To: 9.200.44376.0
Patch Exists: YES
Related CWE: CVE-2006-6334
CPE: a:citrix:presentation_server_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2006
Citrix Presentation Server Client WFICA.OCX ActiveX Component Heap Buffer Overflow Exploit
A heap buffer overflow vulnerability was discovered in the Citrix Presentation Server Client WFICA.OCX ActiveX component. This vulnerability was discovered by Andrew Christensen and Aaron Portnoy and was assigned CVE-2006-6334. The exploit was written by e.b. and tested on Windows XP SP2 (fully patched) English, IE6, wfica.ocx version 9.200.44376.0. The exploit will execute shellcode when IE is closed.
Mitigation:
Users should update to the latest version of the Citrix Presentation Server Client WFICA.OCX ActiveX component.