>
> TITLE:
> Citrix MetaFrame Insecure Default Registry Key Permissions
>
> SECUNIA ADVISORY ID:
> SA21076
>
> VERIFY ADVISORY:
> http://secunia.com/advisories/21076/
>
> CRITICAL:
> Less critical
>
> IMPACT:
> Manipulation of data, Privilege escalation
>
> WHERE:
> Local system
>
> SOFTWARE:
> Citrix MetaFrame 1.x for Windows
> http://secunia.com/product/243/
> Citrix MetaFrame Presentation Server 3.x
> http://secunia.com/product/3805/
> Citrix Presentation Server 4.x
> http://secunia.com/product/5270/
>
> DESCRIPTION:
> A security issue has been reported in Citrix MetaFrame, which can be
> exploited by malicious, local users to manipulate certain sensitive
> data.
>
> The problem is caused due to the installer setting insecure default
> permissions on an unspecified registry key.
>
> Successful exploitation reportedly makes it possible to gain
> escalated privileges.
>
> The security issue affects versions 1.8, 3.0, and 4.0 for Windows
> NT4.0 and 2000.
>
> SOLUTION:
> Apply hotfixes.
> http://support.citrix.com/hotfixes.jsp
>
> PROVIDED AND/OR DISCOVERED BY:
> The vendor credits Andres Tarasco, SIA Group.
>
> ORIGINAL ADVISORY:
> http://support.citrix.com/article/CTX110492
>