Junglewise Threat Intelligence

CVE-2016-9679: Citrix Provisioning Services remote code execution via function pointer overwrite

CVE-2016-9679 · Severity: critical · CVSS 9.8 · Published 2017-01-18

Technologies: Citrix Provisioning Services. Vendors: Citrix.

Executive brief

Citrix Provisioning Services, a tool used to manage and stream operating system images to computers, contains a critical security flaw. An unauthenticated attacker can remotely execute malicious code on the server, potentially leading to a full system takeover. This could allow an intruder to disrupt IT operations, steal sensitive data, or gain a foothold within the corporate network.

Technical details

Citrix Provisioning Services (PVS) versions prior to 7.12 are vulnerable to a memory corruption issue classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The vulnerability allows a remote, unauthenticated attacker to overwrite a function pointer within the application's memory space. By sending specially crafted network traffic to the PVS server, an attacker can redirect the flow of execution to arbitrary code. This results in full system compromise with the privileges of the Provisioning Services process. The issue is resolved in Citrix Provisioning Services version 7.12.

Affected products

  • Citrix Provisioning Services 7.0, 7.1, 7.6, 7.7, 7.8, 7.9, 7.11

Timeline

  • 2017-01-18: disclosed
  • 2017-01-18: advisory

References

Related threats