Citrix Provisioning Services StreamProcess.exe Remote Code Execution (CTX130846)

Critical Nessus Plugin ID 56392


The remote Windows host has an application running that is affected by a remote code execution vulnerability.


The version of the StreamProcess.exe component included with the Citrix Provisioning Services installation running on the remote Windows host is affected by a remote code execution vulnerability in the Ardence.CMessageUtils.fromMgrString() function in Manager.dll. An unauthenticated, remote attacker can exploit this to execute arbitrary code on the remote host with SYSTEM privileges.


Apply the relevant patch referenced in the vendor's advisory.

See Also

Plugin Details

Severity: Critical

ID: 56392

File Name: citrix_provisioning_services_ctx130846.nasl

Version: $Revision: 1.15 $

Type: local

Agent: windows

Family: Windows

Published: 2011/10/05

Modified: 2017/01/26

Dependencies: 51663, 10456

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 9.8

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:citrix:provisioning_services

Required KB Items: SMB/Citrix/Provisioning_Services/Version, SMB/Citrix/Provisioning_Services/Path, SMB/Citrix/Provisioning_Services/StreamProcess.exe

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/09/27

Vulnerability Publication Date: 2011/09/27

Exploitable With

Metasploit (Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020006 Buffer Overflow)

Reference Information

BID: 49803

OSVDB: 75780

EDB-ID: 18478, 18967, 18968, 18969