Citrix patches XenMobile vulnerability

Positive Technologies spots serious flaw in Citrix XenMobile

Citrix has issued a patch for XenMobile, after a security researcher at Positive Technologies spotted a vulnerability in the enterprise mobility management system.

According to researcher Andrey Medov, the flaw in the server component could let attackers read files, including configuration files and encryption keys.

"Exploitation of this vulnerability allows hackers to obtain information that can be useful for breaching the perimeter, as the configuration file often stores domain account credentials for LDAP access," explained Medov, referring to lightweight directory access protocol, servers that are mainly used for central storage of accounts.

"With access to the domain account, a remote attacker can use the obtained data for authentication on other external company resources, including corporate mail, VPN, and web applications."

Medov adds: "Worse still, an attacker who has managed to read the configuration file can access sensitive data, such as database passwords — local PostgreSQL by default and a remote SQL Server database in some cases."

There's no reason to panic, though, as victims would need to follow a malicious link first and the attacker would need some physical access. "However, taking into account that the database is stored inside the corporate perimeter and cannot be accessed from the outside, this attack vector can only be used in complex attacks, for example, with the involvement of an insider accomplice," Medov explained.

The vulnerability is in versions 10.8 to 10.12 of Citrix XenMobile, also called Citrix Endpoint Management, but not in the cloud versions of the system. If your system is at risk, the company is urging users to update their software. The level of risk depends on the version, with Citrix advising some to update immediately, while advising others they can update as part of their regular patching schedule.

The patch addresses the flaw spotted by Medov as well as a handful of related vulnerabilities reported by Glyn Wintle of Tradecraft and Kristian Bremberg of Detectify, Citrix said.

Last year, Positive Technologies spotted a critical vulnerability in Citrix software that affected 80,000 companies, but a survey six weeks later revealed one in five of those companies still hadn't patched the flaw.

Featured Resources

Four cyber security essentials that your board of directors wants to know

The insights to help you deliver what they need

Download now

Data: A resource much too valuable to leave unprotected

Protect your data to protect your company

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

Recommended

Everything you need to know about Citrix
software as a service (SaaS)

Everything you need to know about Citrix

11 Feb 2020
Hackers are taking advantage of Citrix vulnerabilities
hacking

Hackers are taking advantage of Citrix vulnerabilities

17 Jul 2020
Citrix ShareFile review: Slick collaboration, stonking price
cloud storage

Citrix ShareFile review: Slick collaboration, stonking price

20 Dec 2019

Most Popular

46 million Animal Jam accounts leaked after comms software breach
Security

46 million Animal Jam accounts leaked after comms software breach

13 Nov 2020
macOS Big Sur is bricking some older MacBooks
operating systems

macOS Big Sur is bricking some older MacBooks

16 Nov 2020
Huawei Mate 40 Pro 5G review: A tragically brilliant Mate
Mobile Phones

Huawei Mate 40 Pro 5G review: A tragically brilliant Mate

26 Nov 2020