CVE-2016-9679
published 2017-01-18CVE-2016-9679: Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.16%
86.5th percentile
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | provisioning_services | — | — |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Citrix Provisioning Services up to 7.11 memory corruption (Nessus ID 96630 / BID-95620)
vuldb·2026-05-14·CVSS 9.8
CVE-2016-9679 [CRITICAL] Citrix Provisioning Services up to 7.11 memory corruption (Nessus ID 96630 / BID-95620)
A vulnerability was found in Citrix Provisioning Services up to 7.11. It has been declared as critical. This issue affects some unknown processing. Such manipulation leads to memory corruption.
This vulnerability is listed as CVE-2016-9679. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
GHSA-vj86-9q4g-rcw8: Citrix Provisioning Services before 7
ghsa_unreviewed·2022-05-17
CVE-2016-9679 [CRITICAL] CWE-119 GHSA-vj86-9q4g-rcw8: Citrix Provisioning Services before 7
Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
Citrix
CVE-2016-9679: Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
vendor_citrix·2017-01-18·CVSS 9.8
CVE-2016-9679 [CRITICAL] CWE-119 CVE-2016-9679: Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
CVE-2016-9679: Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.
Citrix
Citrix Security Bulletin CTX219580
vendor_citrix·CVSS 9.8
CVE-2016-9676 [CRITICAL] Citrix Security Bulletin CTX219580
Citrix Security Bulletin CTX219580
CVE References: CVE-2016-9676, CVE-2016-9677, CVE-2016-9678, CVE-2016-9679, CVE-2016-9680, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
2017-01-18
Published