First published: Wed Oct 22 2008(Updated: )
Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix XenApp Server SDK | =4.5 | |
Citrix Access Essentials | =1.0 | |
Citrix Access Essentials | =2.0 | |
Tgstation 13 | =4.0 | |
Citrix XenApp Server SDK | <=4.5 | |
Citrix Access Essentials | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4676 is considered a local privilege escalation vulnerability.
To mitigate CVE-2008-4676, users should upgrade to a patched version of Citrix XenApp, Citrix Presentation Server, or Citrix Access Essentials.
CVE-2008-4676 affects Citrix XenApp 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials versions 1.0, 1.5, and 2.0.
CVE-2008-4676 is a local vulnerability, meaning it requires local access for exploitation.
Exploitation of CVE-2008-4676 can allow local users to gain elevated privileges on affected systems.