Citrix

 

Register / Login Home    Forums    Presentation Server 4.0    Latest Posts    Latest News    PSP

 Citrix Site Navigation

 Citrix Home

 Citrix Forums

 Citrix Latest Posts

 Citrix Latest Citrix News

 Citrix Presentation Server 4.5

  Citrix Presentation Server 4.5 Guides

  Citrix PS 4.5 White Papers

  Citrix PS 4.5 Hotfixes

  Citrix PS 4.5 My Experiences

 Citrix Presentation Server 4

  Citrix Installing / Configuring

  Citrix Citrix Guides

  Citrix Citrix Tips

  Citrix Citrix White Papers

  Citrix Hotfixes

  Citrix My Personal Experiences

 Citrix Misc

  Citrix Citrix Web Interface

  Citrix Pre Presentation Server 4.0

  Citrix Citrix Security Bulletins

  Citrix Citrix Client
  Citrix Citrix cca
  Citrix Citrix Printing

  Citrix ICA File

  Citrix Citrix RSS Feeds

  Citrix Contact Us

  Citrix Signup Citrix Newsletter

 

 
 Citrix Site Partners

  Citrix Citrix

  Citrix PSP
  Citrix Xbox

  Citrix Flex Developers

  Citrix Travel In Europe
  Citrix Online Hotel Reservations
  Citrix News of software
  Citrix Resources
  Citrix Linkdiy
  Citrix Web Site Development
  Citrix Fix computer problem
  Citrix Fix slow computer
  Citrix Stop Snoring

  Citrix Perfumes


Welcome to Citrix Guide. I hope you find our citrix articles useful

 

 MetaFrame installer adds a registry key with an insecure access control list
 Citrix Guide Forums > Technical Library > Presentation Server 4.0 Documents > Presentation Server 4.0 Tips / Advanced Concepts
  #1 (permalink)  
Old 09-05-2006, 07:16 PM  MetaFrame installer adds a registry key with an insecure access control list

citrix citrix is offline

Administrator

 
Join Date: May 2006
Posts: 305

Submit Article To > Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq Submit to Spurl

MetaFrame installer adds a registry key with an insecure access control list

Description of Problem
The installers for some versions of MetaFrame add a registry key with an insecure access control list. On vulnerable servers this registry key could potentially be used to elevate the privileges of authenticated users.
This vulnerability is present in versions of MetaFrame up to and including MetaFrame XP 1.0 Feature Release 1. Installations of later versions of MetaFrame and Presentation Server could also be affected if they have at some point been upgraded from a vulnerable version.
Any server running on Windows Server 2003 will not be affected by this as none of the versions supported on this platform add the insecure access control list.

Mitigating Factors
This vulnerability cannot be exploited by anonymous users; to be able to exploit this an attacker would need to be able to log on locally to the server, or be able to make remote registry key changes.

What Customers Should Do
Citrix recommends that affected customers install the released hotfix to address this issue; this can be downloaded from the following location:
http://support.citrix.com/hotfixes.jsp

Acknowledgements
Citrix thanks Andres Tarasco of SIA Group for reporting this issue and working with us to protect our customers.

What Citrix Is Doing
Citrix is proactively notifying customers and channel partners about this potential security issue. An article containing the information in this bulletin is available from the Citrix Knowledge Base at http://support.citrix.com/.

Obtaining Support on this Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Information for contacting Citrix Technical Support is available at http://support.citrix.com/.

Reporting Security Vulnerabilities to Citrix
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities very seriously. If you would like to report a security issue to Citrix, please compose an e-mail to secure@citrix.com containing the exact version of the product in which the vulnerability was found and steps to reproduce the vulnerability.
>> MetaFrame installer adds a registry key with an insecure access control list Reply With Quote
Reply

MetaFrame installer adds a registry key with an insecure access control list « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 08:43 PM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0 RC8


Citrixguide.com is not endorsed by or affiliated with Citrix Systems, Inc. or any of it’s subsidiaries. Installing/Configuring Citrix ::
Citrix Guides :: Citrix Tips/Advanced Concepts :: Citrix White Papers :: Citrix Hotfixes :: Citrix My Experiences :: Citrix Forums