Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Citrix Provisioning Services 'streamprocess.exe' Component Remote Code Execution Vulnerability

Information

Severity

Severity

Critical

Family

Family

Buffer overflow

CVSSv2 Base

CVSSv2 Base

10.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

11 years ago

Modified

Modified

4 years ago

Summary

This host is installed with Citrix Provisioning Services and is prone to remote code execution vulnerability.

Insight

Insight

The flaw is due to an error in the 'streamprocess.exe' component when handling a '0x40020010' type packet. This can be exploited to cause a stack based buffer overflow via a specially crafted packet sent to UDP port 6905.

Affected Software

Affected Software

Citrix Provisioning Services version 5.6 and prior.

Solution

Solution

Upgrade to Citrix Provisioning Services version 5.6 SP1 or later.