-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2022.6293
        CVE-2012-5161 - Vulnerability in Citrix XenApp could result
                        in arbitrary code execution
                              2 December 2022

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           XenApp
Publisher:         Citrix
Operating System:  Windows Server 2008 R2
Resolution:        Patch/Upgrade
CVE Names:         CVE-2012-5161  

Original Bulletin: 
   https://support.citrix.com/article/CTX135066/cve20125161-vulnerability-in-citrix-xenapp-could-result-in-arbitrary-code-execution

Comment: CVSS (Max):  None available when published

- --------------------------BEGIN INCLUDED TEXT--------------------

CVE-2012-5161 - Vulnerability in Citrix XenApp could result in arbitrary code execution

Reference: CTX135066
Category : High
Created  : 11 December 2012
Modified : 23 August 2019

Applicable Products

  o XenApp 6.5 for Windows Server 2008 R2

Description of Problem

A vulnerability has been identified in the XML Service interface of XenApp that
could potentially be used by a remote, unauthenticated attacker to execute
arbitrary code in the context of a service account on a XenApp server. The
vulnerability could potentially be exploited by sending a specially crafted
packet to the vulnerable component.

This vulnerability affects Citrix XenApp versions 6.5 both with, and without,
Feature Pack 1.

This vulnerability has been assigned the following CVE:

    o CVE-2012-5161

Mitigating Factors

In order to exploit this issue, the attacker would need to be able to access
the XML Service interface. In a normal deployment, the XML Service would not be
directly exposed to the Internet.

What Customers Should Do

Hotfixes have been released to address this issue. Citrix strongly recommends
that all customers install these hotfixes, which can be downloaded from the
following locations:

Citrix XenApp 6.5 for Windows Server 2008 R2 with Feature Pack 1: CTX135025 -
Hotfix XA650R01W2K8R2X64033 - For Citrix XenApp 6.5 for Windows Server 2008 R2
- - English

Customers that are not able to upgrade to XenApp 6.5 with Feature Pack 1 may
use the hotfix for the release version of XenApp 6.5 which is available at the
following location: Citrix XenApp 6.5 for Windows Server 2008 R2: CTX135499 -
Hotfix XA650W2K8R2X64036 - For Citrix XenApp 6.5 for Windows Server 2008 R2 -
English

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: https://auscert.org.au/gpg-key/

iQIVAwUBY4mKu8kNZI30y1K9AQiiwg/+IN09Y4EclBffn3bxYwcG7O4KesqjRe41
xQ3GipsJgY8Sw76ryH/RzNYsdC9fHfCFtonTw9W8ahcRnLSBMG4/W7SrTq6G5a3M
LRls1dfAVe3zkrFGlEsli/k2Hyy7UbYPKqxC+olJ9YkCRpPXYYK3jF06RHAPbb+s
iD7yG2ocQoVr9hK4f9EYvhqLPmUP5LUvwlLHv7oMmJpEXOa69QDcU1puooKVdtKW
fC81ua2GdXl6DGPwB/bbUAi+BhGMf1s0a9LUeLPJ6SGm6EEaKVKYEJtmvR1iIfvK
jW43eaI2BUeF/jbYnxrye4ZUC1+IDlRL/ZLX6vVXszDwe+Wqte8gndBR1s9icOIm
QJz3Jso6Zgk6sLET3Ys7wn0n3ssT5EluXKOxKzXpp63kTn1u8rwh3ykiSZtzKEgP
gosJlVNiYCs/0k8E0pKYp02su4Na5AaLDAso5KxGF0Zk2e16f9ODWP0BNOZoE4te
3tIKmqdnMDqurb1HgMMaER5GT9VPUKNRSD68dIzJpjaNgm8PMQmEaJe+31942S5i
h5PzczZZsvrWn9LMsby8zn14zDf6EfRjBwHDbd6cIgWVkA8rWL80/b7krRgqegHD
Ub5kA+KnnNLc6fMC8+Y3AUNEX2h62G24LGYsXiYEnSKy1KK7uuS+GjZGpYVj/C4J
Y4zOC/Jveew=
=KLpd
-----END PGP SIGNATURE-----