Citrix patches XenMobile vulnerability

Positive Technologies spots serious flaw in Citrix XenMobile

Citrix has issued a patch for XenMobile, after a security researcher at Positive Technologies spotted a vulnerability in the enterprise mobility management system.

According to researcher Andrey Medov, the flaw in the server component could let attackers read files, including configuration files and encryption keys.

"Exploitation of this vulnerability allows hackers to obtain information that can be useful for breaching the perimeter, as the configuration file often stores domain account credentials for LDAP access," explained Medov, referring to lightweight directory access protocol, servers that are mainly used for central storage of accounts.

"With access to the domain account, a remote attacker can use the obtained data for authentication on other external company resources, including corporate mail, VPN, and web applications."

Medov adds: "Worse still, an attacker who has managed to read the configuration file can access sensitive data, such as database passwords — local PostgreSQL by default and a remote SQL Server database in some cases."

There's no reason to panic, though, as victims would need to follow a malicious link first and the attacker would need some physical access. "However, taking into account that the database is stored inside the corporate perimeter and cannot be accessed from the outside, this attack vector can only be used in complex attacks, for example, with the involvement of an insider accomplice," Medov explained.

The vulnerability is in versions 10.8 to 10.12 of Citrix XenMobile, also called Citrix Endpoint Management, but not in the cloud versions of the system. If your system is at risk, the company is urging users to update their software. The level of risk depends on the version, with Citrix advising some to update immediately, while advising others they can update as part of their regular patching schedule.

The patch addresses the flaw spotted by Medov as well as a handful of related vulnerabilities reported by Glyn Wintle of Tradecraft and Kristian Bremberg of Detectify, Citrix said.

Last year, Positive Technologies spotted a critical vulnerability in Citrix software that affected 80,000 companies, but a survey six weeks later revealed one in five of those companies still hadn't patched the flaw.

Featured Resources

Consumer choice and the payment experience

A software provider's guide to getting, growing, and keeping customers

Download now

Prevent fraud and phishing attacks with DMARC

How to use domain-based message authentication, reporting, and conformance for email security

Download now

Business in the new economy landscape

How we coped with 2020 and looking ahead to a brighter 2021

Download now

How to increase cyber resilience within your organisation

Cyber resilience for dummies

Download now

Recommended

ProtectedBy.AI’s CodeLock blocks malware at source code level
software as a service (SaaS)

ProtectedBy.AI’s CodeLock blocks malware at source code level

9 Jun 2021
CISOs aren’t leading by example when it comes to cyber security
cyber security

CISOs aren’t leading by example when it comes to cyber security

24 May 2021
New report highlights the need for diversity in cyber security recruitment
cyber security

New report highlights the need for diversity in cyber security recruitment

28 Apr 2021
Hackers are taking advantage of Citrix vulnerabilities
hacking

Hackers are taking advantage of Citrix vulnerabilities

17 Jul 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

16 Jun 2021
What is HTTP error 400 and how do you fix it?
Network & Internet

What is HTTP error 400 and how do you fix it?

16 Jun 2021
Ten-year-old iOS 4 recreated as an iPhone app
iOS

Ten-year-old iOS 4 recreated as an iPhone app

10 Jun 2021