Citrix EdgeSight Load Tester Buffer Overflow

critical Nessus Plugin ID 55927

Synopsis

It is possible to execute code on the remote server using a stack overflow vulnerability in Citrix EdgeSight Load Tester.

Description

A stack overflow vulnerability exists in the Citrix EdgeSight Load Tester software installed on the remote host.

By sending a specially crafted message to the server, a remote attacker can leverage this vulnerability to execute arbitrary code on the server as the SYSTEM account.

Versions prior to 3.8.1 are affected.

Solution

Citrix has released version 3.8.1, which resolves the issue.

See Also

https://www.citrix.com/

https://support.citrix.com/article/CTX129699

https://www.zerodayinitiative.com/advisories/ZDI-11-226/

Plugin Details

Severity: Critical

ID: 55927

File Name: citrix_eslt_heap_overflow.nasl

Version: 1.8

Type: remote

Agent: windows

Family: Windows

Published: 8/22/2011

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: Services/CitrixESLT

Exploit Ease: No known exploits are available

Patch Publication Date: 6/27/2011

Vulnerability Publication Date: 6/27/2011

Reference Information

BID: 48385

IAVB: 2011-B-0084-S