APP: Citrix Access Gateway Plug-in for Windows nsepacom ActiveX Control Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Citrix Access Gateway Plug-in for Windows. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

The Citrix Access Gateway Plug-in ActiveX control is prone to multiple remote code-execution vulnerabilities because it fails to perform adequate boundary checks on user-supplied input. Attackers may exploit these issues to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions. Citrix Access Gateway Plug-in 9.3.49.5 is vulnerable; other versions may also be affected.

Affected Products

Citrix access_gateway_plug-in

References

BugTraq: 54754

CVE: CVE-2011-2592

Short Name
APP:CITRIX:NSEPACOM-BOF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Access ActiveX Buffer CVE-2011-2592 Citrix Control Gateway Overflow Plug-in Windows bid:54754 for nsepacom
Release Date
01/09/2013
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Citrix

CVSS Score

9.3

Found a potential security threat?