Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2008/0845 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41102 | vdb entry |
http://support.citrix.com/article/CTX116227 | patch vendor advisory |
http://www.securitytracker.com/id?1019605 | vdb entry |