>> Citrix Presentation Server and MetaFrame Print Provider Buffer Overflow Vulnerability
Title : Citrix Presentation Server and MetaFrame Print Provider Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-0328 CVE ID : CVE-2007-0444
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-24
Technical Description
A vulnerability has been identified in Citrix Presentation Server and Citrix MetaFrame XP, which could be exploited by local or remote attackers to cause a denial of service or take complete control of an affected system. This issue is due to a buffer overflow error in the client print provider (CPPROV.DLL) that fails to properly handle malformed calls to the "EnumPrintersW()" and "OpenPrinter()" functions, which could be exploited by malicious local users to obtain elevated privileges via a malformed API call, or by remote unauthenticated attackers to execute arbitrary commands with SYSTEM privileges via a specially crafted RPC request.