CVE-2010-2991Code Injection in Citrix Online Plug-in FOR Windows FOR Xenapp Xendesktop

CWE-94Code Injection4 documents3 sources
Severity
9.3CRITICALNVD
EPSS
9.5%
top 7.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 17

Description

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages10 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-x85q-ch42-gg6w: The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp2022-05-17

📋Vendor Advisories

2
Citrix
CVE-2010-2991: The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp2010-08-11
Citrix
Citrix Security Bulletin CTX125976