9.3
CVSSv2

CVE-2010-2991

Published: 11/08/2010 Updated: 12/08/2010
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop prior to 12.0.3 allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.

Vulnerable Product Search on Vulmon Subscribe to Product

citrix online plug-in for windows for xenapp \\& xendesktop 11.1

citrix online plug-in for windows for xenapp \\& xendesktop