Security Researcher Warns About Citrix Vulnerability - InformationWeek
Software // Enterprise Applications
02:46 PM
Connect Directly
Ransomware: Latest Developments & How to Defend Against Them
Nov 01, 2017
Ransomware is one of the fastest growing types of malware, and new breeds that escalate quickly ar ...Read More>>

Security Researcher Warns About Citrix Vulnerability

The flaw could allow an attacker user-level access to execute remote commands on Citrix servers.

A security consultancy has identified a vulnerability that could allow an attacker to gain "user access level on integrated remote Citrix servers."

GnuCitizen, which identifies itself as a "cutting-edge think tank" and a "creative hacker organization," has posted a warning about a cross-site request forgery attack that can be made in conjunction with a malicious Web site to trick a Citrix user into opening a specially crafted Citrix independent computer architecture (ICA) file that would compromise his or her system.

If successful, the attacker could gain the ability to execute remote commands at the victim's access level.

"The success of the attack [relies] on the fact that the victim (the proxy) is part of a Citrix ring to which he/she can perform pass-through authentication," explains Petko D. Petkov, founder of GnuCitizen and its lead researcher, in a blog post. "Once a connection is instantiated, the victim will unwillingly and transparently login into Citrix and perform several commands specified by the attacker. The attacker can simply instruct the remote desktop to download files from a remote TFTP server and execute them locally. Once the attack is performed, the local connection is terminated and the Citrix session is cleared. No user interaction is required!"

In an e-mail, Petkov characterized the vulnerability as quite severe. "It is a remote command execution attack which cannot be easily fixed, mainly because it relies on features rather than bugs," he said. "If the attacker tricks a user from the targeted network into visiting a malicious Web site or opening a specially crafted ICA file, then they might be able to gain access to critical corporate assets. The attack is very simple and highly effective. Citrix is also a very popular platform. This makes this issue extremely problematic."

Petkov said that while he doubts the vulnerability is widely known, "anyone with the right methodology and mindset will be able to rediscover it."

Citrix said in an e-mailed statement that it "has become aware of recent blog postings relating to insecure deployment of Citrix products." The company said that while no specific vulnerability was identified, it recommends that its customers follow the security practices outlined on its Web site.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
[Interop ITX 2017] State Of DevOps Report
[Interop ITX 2017] State Of DevOps Report
The DevOps movement brings application development and infrastructure operations together to increase efficiency and deploy applications more quickly. But embracing DevOps means making significant cultural, organizational, and technological changes. This research report will examine how and why IT organizations are adopting DevOps methodologies, the effects on their staff and processes, and the tools they are utilizing for the best results.
Register for InformationWeek Newsletters
White Papers
Current Issue
2017 State of IT Report
In today's technology-driven world, "innovation" has become a basic expectation. IT leaders are tasked with making technical magic, improving customer experience, and boosting the bottom line -- yet often without any increase to the IT budget. How are organizations striking the balance between new initiatives and cost control? Download our report to learn about the biggest challenges and how savvy IT executives are overcoming them.
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll