vendor:
XenApp and XenDesktop
by:
n.runs AG
7.5
CVSS
HIGH
Heap Corruption in Citrix XML Service
119
CWE
Product Name: XenApp and XenDesktop
Affected Version From: See the Citrix security bulletin [2] for a list
Affected Version To: See the Citrix security bulletin [2] for a list
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
n.runs-SA-2011.002
A heap corruption vulnerability has been found in the Citrix XML Service of XenApp and XenDesktop which is installed on every server used for sharing applications. The issue can be triggered with network access to the system running the XML service. By sending a POST request to a really long non-existent extension DLL some further processing is done in the XML service. This processing leads to a heap corruption which can be used to execute arbitrary code on the server running the XML service.
Mitigation:
See the Citrix security bulletin [2] for a list of affected versions and patches.