Junglewise Threat Intelligence

CVE-2016-9677: Citrix Provisioning Services information disclosure of kernel addresses

CVE-2016-9677 · Severity: medium · CVSS 5.3 · Published 2017-01-18

Technologies: Citrix Provisioning Services. Vendors: Citrix.

Executive brief

Citrix Provisioning Services, a tool used to manage and stream operating system images to computers, contains a security flaw that could allow an attacker to view sensitive internal system memory addresses. While this does not directly allow for data theft or system takeover, it provides critical information that can be used to bypass security protections in more complex attacks. Organizations should update to version 7.12 or later to resolve this issue.

Technical details

Citrix Provisioning Services versions prior to 7.12 are vulnerable to an information disclosure flaw (CWE-200). The vulnerability allows a remote attacker to obtain sensitive kernel address information. While the specific vector is not detailed in the advisory, the CVSS vector indicates the flaw is reachable over the network without authentication or user interaction. This type of leak is typically used to bypass Address Space Layout Randomization (ASLR), facilitating the development of more severe exploits such as remote code execution. The issue is resolved in Citrix Provisioning Services 7.12.

Affected products

  • Citrix Provisioning Services Before 7.12

Timeline

  • 2016-11-23: other: CVE reserved date
  • 2017-01-18: disclosed: Initial NVD publication
  • 2017-01-18: advisory: Vendor advisory CTX219580 released

References