The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document that triggers the reading of a .ICA file.
2010-08-11T20:00:01.437
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | online_plug-in_for_windows_for_xenapp_\&_xendesktop | ≤ 12.0 | Yes |
Application | citrix | online_plug-in_for_windows_for_xenapp_\&_xendesktop | 11.1 | Yes |