First published: Mon Jul 24 2006(Updated: )
Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix MetaFrame | =1.8 | |
Tgstation 13 | =4.0 | |
Citrix Presentation Server | =3.0 | |
Citrix MetaFrame | =1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3779 is considered a medium severity vulnerability due to the potential for privilege escalation by authenticated remote users.
To fix CVE-2006-3779, ensure that proper access control lists (ACLs) are set for the affected registry keys.
CVE-2006-3779 affects Citrix MetaFrame up to version 1.8, Citrix Presentation Server version 4.0, and Citrix MetaFrame Presentation Server version 3.0 on Windows 2000.
Yes, CVE-2006-3779 can be exploited remotely by authenticated users to gain elevated privileges.
CVE-2006-3779 is specifically noted to not affect installations on Windows Server 2003.