CVE-2016-9678
published 2017-01-18CVE-2016-9678: Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
PriorityP348critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.07%
86.1th percentile
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Citrix Provisioning Services up to 7.11 use after free (Nessus ID 96630 / BID-95620)
vuldb·2026-05-14·CVSS 9.8
CVE-2016-9678 [CRITICAL] Citrix Provisioning Services up to 7.11 use after free (Nessus ID 96630 / BID-95620)
A vulnerability was found in Citrix Provisioning Services up to 7.11. It has been classified as critical. This vulnerability affects unknown code. This manipulation causes use after free.
This vulnerability is tracked as CVE-2016-9678. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-p5rw-9673-832m: Use-after-free vulnerability in Citrix Provisioning Services before 7
ghsa_unreviewed·2022-05-17
CVE-2016-9678 [CRITICAL] CWE-416 GHSA-p5rw-9673-832m: Use-after-free vulnerability in Citrix Provisioning Services before 7
Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
Citrix
CVE-2016-9678: Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
vendor_citrix·2017-01-18·CVSS 9.8
CVE-2016-9678 [CRITICAL] CWE-416 CVE-2016-9678: Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
CVE-2016-9678: Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.
Citrix
Citrix Security Bulletin CTX219580
vendor_citrix·CVSS 9.8
CVE-2016-9676 [CRITICAL] Citrix Security Bulletin CTX219580
Citrix Security Bulletin CTX219580
CVE References: CVE-2016-9676, CVE-2016-9677, CVE-2016-9678, CVE-2016-9679, CVE-2016-9680, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No writeups or analysis indexed.
2017-01-18
Published