Executive brief
Palo Alto Networks Terminal Services Agent, which identifies users in multi-user environments for security policy enforcement, contains a vulnerability that allows an attacker to impersonate other users. This could allow an unauthorized individual to bypass security controls or perform actions that are incorrectly attributed to a different person, potentially leading to unauthorized access or data manipulation. Organizations should update to version 7.0.7 or later to resolve this issue.
Technical details
A spoofing vulnerability exists in the Palo Alto Networks Terminal Services (TS) Agent. The TS Agent is responsible for mapping IP addresses and port ranges to specific user identities in environments like Citrix or Microsoft Terminal Services. Due to an unspecified flaw, an attacker can spoof the identity of another authenticated user. The vulnerability is network-reachable and requires no prior privileges or user interaction. Successful exploitation allows an attacker to bypass identity-based security policies or frame other users for malicious activity. The issue is resolved in Terminal Services Agent version 7.0.7.
Affected products
- Palo Alto Networks Terminal Services Agent 6.0, 7.0.6 and earlier
Timeline
- 2017-01-26: advisory: Vendor advisory published by Palo Alto Networks
- 2017-01-27: disclosed: NVD publication date