>
> TITLE:
> Citrix MetaFrame Insecure Default Registry Key Permissions
>
> SECUNIA ADVISORY ID:
> SA21076
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Less critical
>
> IMPACT:
> Manipulation of data, Privilege escalation
>
> WHERE:
> Local system
>
> SOFTWARE:
> Citrix MetaFrame 1.x for Windows
>
> Citrix MetaFrame Presentation Server 3.x
>
> Citrix Presentation Server 4.x
>
>
> DESCRIPTION:
> A security issue has been reported in Citrix MetaFrame, which can be
> exploited by malicious, local users to manipulate certain sensitive
> data.
>
> The problem is caused due to the installer setting insecure default
> permissions on an unspecified registry key.
>
> Successful exploitation reportedly makes it possible to gain
> escalated privileges.
>
> The security issue affects versions 1.8, 3.0, and 4.0 for Windows
> NT4.0 and 2000.
>
> SOLUTION:
> Apply hotfixes.
>
>
> PROVIDED AND/OR DISCOVERED BY:
> The vendor credits Andres Tarasco, SIA Group.
>
> ORIGINAL ADVISORY:
>
>