APP: Citrix Provisioning Services streamprocess.exe Component Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Citrix Provisioning Services. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the affected application.

Extended Description

Citrix Provisioning Services is prone to a remote code-execution vulnerability. An attacker can exploit this vulnerability to execute arbitrary code in the context of the SYSTEM user. The issue affects versions prior to Citrix Provisioning Services 5.6 SP1.

Affected Products

Citrix provisioning_services

Short Name
APP:CITRIX:STREAMPROCESS-BOF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Buffer Citrix Component Overflow Provisioning Services bid:45914 bid:49803 streamprocess.exe
Release Date
11/21/2011
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
Port
UDP/6905
False Positive
Unknown
Vendors

Citrix

Found a potential security threat?