Executive brief
Citrix Provisioning Services, a tool used to manage and stream operating system images to computers, contains a critical security flaw. An attacker can exploit this vulnerability to take complete control of the server without needing any login credentials. This could lead to a total compromise of the infrastructure used to deploy virtual desktops and servers across the organization.
Technical details
A buffer overflow vulnerability (CWE-119) exists in Citrix Provisioning Services versions prior to 7.12. The flaw is reachable over the network and does not require authentication or user interaction. By sending specially crafted data to the service, an attacker can trigger a memory corruption event to execute arbitrary code with high privileges on the host system. Citrix addressed this issue in version 7.12 and provided security bulletin CTX219580 for affected customers.
Affected products
- Citrix Provisioning Services 7.0, 7.1, 7.6, 7.7, 7.8, 7.9, 7.11
Timeline
- 2016-11-23: disclosed: CVE assigned
- 2017-01-18: advisory: NVD publication date
- 2017-01-18: patched: Citrix released version 7.12 to address the issue