book
Article ID: CTX277455
calendar_today
Updated On:
Description
Description
A
high severity issue has been discovered in Citrix StoreFront that, if exploited, would allow an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
This issue has the following identifier:
The issue affects the following supported Current Release (CR) versions of Citrix StoreFront:
- Citrix StoreFront before 2006
The issue affects the following supported Long Term Service Release (LTSR) versions of Citrix StoreFront:
- Citrix StoreFront 1912 LTSR before CU1 (1912.0.1000)
- Citrix StoreFront 3.12 for 7.15 LTSR before CU5 Hotfix (3.12.5001)
- Citrix StoreFront 3.0 for 7.6 LTSR before CU8 Hotfix (3.0.8001)
Note that Citrix StoreFront is included as part of Citrix Virtual Apps and Desktops. Therefore, some customers may be affected who have not independently installed Citrix StoreFront.
Customers running Citrix Virtual Apps and Desktops 2003 should note that the version of Citrix StoreFront included in that release, 1912 LTSR, is one of the affected versions.
Resolution
Mitigating Factors
If users are not in the same Microsoft Active Directory domain as the Citrix StoreFront server, the vulnerability is not exploitable, even if the users are authenticated in a transitively trusted domain. Note that this applies even if the user is logged into the Citrix StoreFront server.
What Customers Should Do
The issue has been addressed in the following Citrix StoreFront versions:
- Citrix StoreFront 1912 CU1 (1912.0.1000) and later versions of Citrix StoreFront 1912 LTSR
- Citrix StoreFront 3.0 for 7.6 LTSR CU8 Hotfix (3.0.8001) and later versions of StoreFront 3.0 for 7.6 LTSR
- Citrix StoreFront 3.12 for 7.15 LTSR CU5 Hotfix (3.12.5001) and later versions of StoreFront 3.12 for 7.15 LTSR
Citrix strongly recommends that customers running affected versions of Citrix StoreFront, both CR and LTSR versions,upgrade to a fixed version as soon as possible.
The latest versions of Citrix StoreFront can be downloaded from the following location:
https://www.citrix.com/downloads/storefront/ https://support.citrix.com/article/CTX277537 https://support.citrix.com/article/CTX277538
Acknowledgements
Citrix would like to thank Harrison Neal of Patch Advisor for working with us to protect Citrix customers.
What Citrix Is Doing
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at
http://support.citrix.com/
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at
https://www.citrix.com/support/open-a-support-case.html
Reporting Security Vulnerabilities
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously.
For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please visit the Citrix Trust Center at
https://www.citrix.com/about/trust-center/vulnerability-process.html
Changelog
Date | Change |
2020-09-08 | Initial Publication |
2020-09-10 | Change in page formatting |
2020-09-10 | Update to the affected versions |
Problem Cause
Security vulnerability