Citrix Presentation Server Client Unspecified Code Execution
Friday, 02 March 2007 by Michel Roth
A vulnerability has been reported in Citrix Presentation Server Client, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error within the support for ICA connections through a proxy server. This may be exploited to execute arbitrary code when a user e.g. visits a malicious web site.

The vulnerability reportedly affects versions prior to 10.0.

Read the Citrix advisory here.

Related Items:

0-Day Microsoft Word 2000 Unspecified Code Execution Vulnerability (5 September 2006)
Warning: 0-Day Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability (6 November 2006)
Zero Day Microsoft Word Unspecified Code Execution Vulnerability (20 May 2006)
Citrix ICA Client ActiveX Control Heap Overflow Vulnerability (6 December 2006)
Warning: Microsoft Windows WMF Handling Arbitrary Code Execution - Exploit In the Wild (29 December 2005)
Microsoft Windows "itss.dll" Heap Corruption Unpatched Vulnerability (10 May 2006)
Citrix Web Interface On-line Help Feature Cross Site Scripting Vulnerability (19 December 2007)
0-Day Microsoft Excel Unspecified Code Execution Vulnerability (19 June 2006)
Internet Explorer "object" Tag Memory Corruption Code Execution (26 April 2006)
Wyse Winterm 1125SE IP Option Length Denial of Service (12 August 2005)
Comments (0)add feed
password
 

busy