Citrix EdgeSight Load Tester Buffer Overflow

Critical Nessus Plugin ID 55927


It is possible to execute code on the remote server using a stack overflow vulnerability in Citrix EdgeSight Load Tester.


A stack overflow vulnerability exists in the Citrix EdgeSight Load Tester software installed on the remote host.

By sending a specially crafted message to the server, a remote attacker can leverage this vulnerability to execute arbitrary code on the server as the SYSTEM account.

Versions prior to 3.8.1 are affected.


Citrix has released version 3.8.1, which resolves the issue.

See Also

Plugin Details

Severity: Critical

ID: 55927

File Name: citrix_eslt_heap_overflow.nasl

Version: $Revision: 1.5 $

Type: remote

Agent: windows

Family: Windows

Published: 2011/08/22

Modified: 2013/06/03

Dependencies: 55926

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

Required KB Items: Services/CitrixESLT

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2011/06/27

Vulnerability Publication Date: 2011/06/27

Reference Information

BID: 48385

OSVDB: 73233

IAVB: 2011-B-0084