CVE-2007-2850: Critical severity Citrix Access Essentials vulnerability
The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2850?
CVE-2007-2850 is classified as a medium severity vulnerability due to its potential to bypass network security policies.
How do I fix CVE-2007-2850?
To fix CVE-2007-2850, apply the latest patches released by Citrix for affected versions of MetaFrame and Access Essentials.
What versions of Citrix software are affected by CVE-2007-2850?
CVE-2007-2850 affects Citrix MetaFrame Presentation Server versions 3.0 and 4.0, as well as Citrix Access Essentials versions 1.0 and 1.5.
What type of attacks can exploit CVE-2007-2850?
CVE-2007-2850 can be exploited by remote attackers to connect to arbitrary TCP ports, thereby bypassing network security measures.
Is CVE-2007-2850 a zero-day vulnerability?
No, CVE-2007-2850 is not a zero-day vulnerability as it was publicly disclosed and has patches available.