Citrix patches XenMobile vulnerability
Positive Technologies spots serious flaw in Citrix XenMobile
Citrix has issued a patch for XenMobile, after a security researcher at Positive Technologies spotted a vulnerability in the enterprise mobility management system.
According to researcher Andrey Medov, the flaw in the server component could let attackers read files, including configuration files and encryption keys.
"Exploitation of this vulnerability allows hackers to obtain information that can be useful for breaching the perimeter, as the configuration file often stores domain account credentials for LDAP access," explained Medov, referring to lightweight directory access protocol, servers that are mainly used for central storage of accounts.
"With access to the domain account, a remote attacker can use the obtained data for authentication on other external company resources, including corporate mail, VPN, and web applications."
Medov adds: "Worse still, an attacker who has managed to read the configuration file can access sensitive data, such as database passwords — local PostgreSQL by default and a remote SQL Server database in some cases."
There's no reason to panic, though, as victims would need to follow a malicious link first and the attacker would need some physical access. "However, taking into account that the database is stored inside the corporate perimeter and cannot be accessed from the outside, this attack vector can only be used in complex attacks, for example, with the involvement of an insider accomplice," Medov explained.
The vulnerability is in versions 10.8 to 10.12 of Citrix XenMobile, also called Citrix Endpoint Management, but not in the cloud versions of the system. If your system is at risk, the company is urging users to update their software. The level of risk depends on the version, with Citrix advising some to update immediately, while advising others they can update as part of their regular patching schedule.
The patch addresses the flaw spotted by Medov as well as a handful of related vulnerabilities reported by Glyn Wintle of Tradecraft and Kristian Bremberg of Detectify, Citrix said.
Last year, Positive Technologies spotted a critical vulnerability in Citrix software that affected 80,000 companies, but a survey six weeks later revealed one in five of those companies still hadn't patched the flaw.
The ultimate law enforcement agency guide to going mobile
Best practices for implementing a mobile device programFree download
The business value of Red Hat OpenShift
Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShiftFree download
Managing security and risk across the IT supply chain: A practical approach
Best practices for IT supply chain securityFree download
Digital remote monitoring and dispatch services’ impact on edge computing and data centres
Seven trends redefining remote monitoring and field service dispatch service requirementsFree download