« Volver al listado

CVE-2008-4676

Estado: ModificadaMedia (6.8)—

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-4676",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-10-22T10:30:01.660",
  "references": [
    {
      "url": "http://secunia.com/advisories/32017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.citrix.com/article/CTX116310",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/31484",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1020954",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2702",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45507",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32017",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.citrix.com/article/CTX116310",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/31484",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020954",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2702",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45507",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        },
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file.  NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en Citrix XenApp (formalmente Presentation Server) 4.5 Feature Pack 1 y versiones anteriores, Presentation Server 4.0, y Access Essentials 1.0, 1.5, y 2.0 permite a los usuarios locales obtener privilegios a través de vectores de ataque desconocidos relativos a la creación de un archivo no especificado. NOTA: esto debería de ser el mismo asunto que CVE-2008-3485, pero el anuncio del vendedor es tan impreciso como para ser cierto."
    }
  ],
  "lastModified": "2026-06-16T22:58:17.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:citrix:access_essentials:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FF9F197-991D-4920-BE9A-2E3495E76CD2"
            },
            {
              "criteria": "cpe:2.3:a:citrix:access_essentials:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21B89150-1806-481D-B0D9-FD37BA4798D1"
            },
            {
              "criteria": "cpe:2.3:a:citrix:access_essentials:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D04505CA-D715-4094-9B39-61FA8BDB3A4B"
            },
            {
              "criteria": "cpe:2.3:a:citrix:presentation_server:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "967F31B0-0299-4BCE-91E5-45E2B38CFCE2"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xenapp:*:fp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60589E82-E176-4C0C-9034-B3E5C1F6B3D6",
              "versionEndIncluding": "4.5"
            },
            {
              "criteria": "cpe:2.3:a:citrix:xenapp:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FBAEA3D-7E35-4C89-B416-8CDEB3286253"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}