Junglewise Threat Intelligence

CVE-2016-9680: Citrix Provisioning Services information disclosure in kernel memory

CVE-2016-9680 · Severity: high · CVSS 7.5 · Published 2017-01-18

Technologies: Citrix Provisioning Services. Vendors: Citrix.

Executive brief

Citrix Provisioning Services, a tool used to manage and stream operating system images to computers, contains a vulnerability that could allow an attacker to access sensitive information. By exploiting this flaw, an unauthorized user could read data from the system's kernel memory, potentially leading to the exposure of credentials or other confidential system data. This could compromise the security of the entire virtual desktop infrastructure.

Technical details

An information disclosure vulnerability exists in Citrix Provisioning Services versions prior to 7.12. The flaw allows a remote, unauthenticated attacker to read sensitive information from kernel memory. While the specific technical vector is not detailed in the advisory, the vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Successful exploitation could allow an attacker to bypass security boundaries and access data that should be protected by the operating system kernel. Users are advised to upgrade to Citrix Provisioning Services 7.12 or later to mitigate this risk.

Affected products

  • Citrix Provisioning Services Before 7.12

Timeline

  • 2016-11-23: disclosed: CVE reserved date
  • 2017-01-18: advisory: NVD publication date
  • 2017-01-18: patched: Citrix released version 7.12 to address the issue

References

Related threats