CVE-2016-9677
published 2017-01-18CVE-2016-9677: Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
PriorityP424medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.47%
70.8th percentile
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2016-9677: Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
vendor_citrix·2017-01-18·CVSS 5.3
CVE-2016-9677 [MEDIUM] CWE-200 CVE-2016-9677: Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
CVE-2016-9677: Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
Citrix
Citrix Security Bulletin CTX219580
vendor_citrix·CVSS 9.8
CVE-2016-9676 [CRITICAL] Citrix Security Bulletin CTX219580
Citrix Security Bulletin CTX219580
CVE References: CVE-2016-9676, CVE-2016-9677, CVE-2016-9678, CVE-2016-9679, CVE-2016-9680, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
VulDB
Citrix Provisioning Services up to 7.11 Kernel Memory information disclosure (Nessus ID 96630 / BID-95620)
vuldb·2026-05-14·CVSS 5.3
CVE-2016-9677 [MEDIUM] Citrix Provisioning Services up to 7.11 Kernel Memory information disclosure (Nessus ID 96630 / BID-95620)
A vulnerability was found in Citrix Provisioning Services up to 7.11 and classified as problematic. This affects an unknown part. The manipulation results in information disclosure (Kernel Memory).
This vulnerability is identified as CVE-2016-9677. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-5g9m-x68j-5mr2: Citrix Provisioning Services before 7
ghsa_unreviewed·2022-05-17
CVE-2016-9677 [MEDIUM] CWE-200 GHSA-5g9m-x68j-5mr2: Citrix Provisioning Services before 7
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-18
Published