APP: Citrix Provisioning Services streamprocess.exe Integer Underflow

This signature detects attempts to exploit a known flaw in Citrix Provisioning Service. A remote, unauthenticated attacker could exploit this vulnerability by sending a malicious request to the target service. A successful attack may allow execution of arbitrary code on the target machine within the security context of the service, which is SYSTEM. If the attack is not successful, the vulnerable service may terminate abnormally, causing a denial-of-service condition.

Extended Description

Citrix Provisioning Services is prone to a remote code-execution vulnerability. Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application. Citrix Provisioning Services versions 5.6 SP1 and prior are affected.

Affected Products

Citrix provisioning_services

Short Name
APP:CITRIX:PROVISIONINGSERV-UF
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Citrix Integer Provisioning Services Underflow bid:49803 streamprocess.exe
Release Date
01/25/2012
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3655
Port
UDP/6905
False Positive
Unknown
Vendors

Citrix

Found a potential security threat?