| Citrix MetaFrame Presentation Server Client Debugging Security Issue |
| Monday, 22 November 2004 by Michel Roth | |||
|
... A security issue has been reported in Citrix MetaFrame Presentation Server Client, which can be exploited by malicious users to gain knowledge of sensitive information. The problem is that the client includes a debugging feature (disabled by default), which can be used to create a log file of the keyboard scan codes sent during an ICA connection. This can be exploited to gain knowledge of sensitive information (e.g. another user's credentials) by tricking that user into using a client with the debugging feature enabled. ... Thincomputing.net mentioned this security issue some three weeks earlier and another way around it. Read the whole story at the secunia website. The original article (CTX105215) on the Citrix website can be found here.
Show/Hide comment form
|
|||
