First published: Wed Aug 06 2008(Updated: )
Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Presentation Server | <=3.0 | |
Citrix XenApp | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3485 is considered a high-severity vulnerability due to the potential privilege escalation it allows to local users.
To fix CVE-2008-3485, ensure that the installation path is secure and review permissions to prevent malicious files like icabar.exe from being executed.
CVE-2008-3485 affects Citrix MetaFrame Presentation Server versions up to 3.0 and Citrix Xp versions up to 1.0.
CVE-2008-3485 is associated with local privilege escalation attacks through an untrusted search path vulnerability.
CVE-2008-3485 requires local access to the system to exploit, meaning it cannot be directly exploited remotely.