Junglewise Threat Intelligence

CVE-2016-9678: Citrix Provisioning Services use-after-free remote code execution

CVE-2016-9678 · Severity: critical · CVSS 9.8 · Published 2017-01-18

Technologies: Citrix Provisioning Services. Vendors: Citrix.

Executive brief

Citrix Provisioning Services, a tool used to manage and stream operating system images to computers, contains a critical security flaw. An attacker can exploit this vulnerability to take full control of the affected server and execute unauthorized commands. This could lead to a complete compromise of the provisioning infrastructure, data theft, or disruption of service for all connected workstations.

Technical details

A use-after-free vulnerability (CWE-416) exists in Citrix Provisioning Services prior to version 7.12. The flaw is reachable over the network without authentication, as indicated by the CVSS vector AV:N/AC:L/PR:N. While the specific vulnerable component or vector is not detailed in the advisory, use-after-free bugs typically occur when a program continues to use a pointer after it has been freed, potentially allowing an attacker to corrupt memory and redirect execution flow. Successful exploitation allows for remote code execution (RCE) with the privileges of the service. Users are advised to upgrade to version 7.12 or later.

Affected products

  • Citrix Provisioning Services before 7.12

Timeline

  • 2017-01-18: disclosed
  • 2017-01-18: advisory: NVD publication date

References

Related threats