The Channel logo

News

By | John Leyden 6th March 2007 14:21

Windows-like flaw hits Citrix

Welcome to our world

A flaw in Citrix's Presentation Server Client creates a means for hackers to compromise machines running the popular thin-client application.

The vulnerability stems from an unspecified bug involving support for Independent Computing Architecture (ICA) connections through a proxy server. ICA is an application server protocol used by Citrix products.

If successfully exploited, the vulnerability might be harnessed to inject malware onto vulnerable systems running maliciously constructed websites.

The exploit scenario is all too familiar to users of Windows fat client PCs, but unusual to users of generally far more secure thin clients, contributing to the bug's critical rating.

Users are advised to update to version 10.0 of Citrix's software to guard against possible attacks based on the flaw, which affects Citrix Presentation Server Client version 9.x and below. Citrix credits the discovery of the flaw to Karl Lynn of Juniper Networks. Citrix's advisory on the flaw can be found here. ®

alert Send corrections

Opinion

Trevor Pott

Why aren't you, personally, stopping the moronocalypse?
Star Trek Into Darkness

Chris Mellor

Federation fissiparousness to form co-ordinated divisions
iot_internet_of_things

Chris Mellor

EMC is ahead overall with HDS mounting an IoT catch-up

Features

Lego gandalf by https://www.flickr.com/photos/isherwoodchris/  CC 2.0 https://creativecommons.org/licenses/by-sa/2.0/ attribution sharealike
Why interconnectivity in the cloud is tougher than just stacking bricks
Handing over dollars picture via Shutterstock
Steve Ballmer. Pic:  Aanjhan Ranganathan
Nokia is the biggest write-off yet, but it wasn't the first
Confused computer keyboard
Last Christmas, I gave you my Cloud, the very next day you gave it away