Vulnerabilities > CVE-2012-5161 - Remote Code Execution vulnerability in Citrix Xenapp 6.5.0.0

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
citrix
critical
nessus

Summary

The XML Service interface in Citrix XenApp 6.5 and 6.5 Feature Pack 1 allows remote attackers to execute arbitrary code via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Citrix
2

Nessus

NASL familyWindows
NASL idCITRIX_XENAPP_CTX135066.NASL
descriptionThe version of Citrix XenApp installed on the remote Windows host is potentially affected by an unspecified vulnerability in the XML service interface. An unauthenticated, remote attacker can exploit this to execute arbitrary code on the remote host.
last seen2020-06-01
modified2020-06-02
plugin id63339
published2012-12-27
reporterThis script is Copyright (C) 2012-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/63339
titleCitrix XenApp XML Service Interface Crafted Packet Parsing Remote Code Execution (CTX135066)