News: 1595349547

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace could let remote attacker pwn host machine

(2020/07/21)


Research outfit Pen Test Partners has uncovered a vulnerability in Citrix Workspace potentially allowing a privilege escalation to lead to full remote compromise of the host machine.

The flaw, CVE-2020-8207 ( [1]not yet reserved at the time of publication ), sees Workspace's automatic update feature abused to gain access to a vulnerable Workspace installation, with the attack vector being a [2]named pipe .

The hole [3]has been patched and users of Citrix Workspace should install the latest version (2006.1 or 1912 LTSR CU1) sooner rather than later.

While Citrix asserted that the vuln only affects Workspace installations installed by either a local or domain admin (and not a bog-standard user account) any flaw in a widely used remote-working tool, in this day and age, is going to catch the world's eye rather quickly.

Ken Munro of Pen Test Partners told El Reg : "With the move to remote working, privilege escalation issues in remote desktop systems allow newly remote workers and hackers who have compromised accounts to break out of the secure environment."

PTP's Ceri Coburn figured out how to leverage Workspace's automatic update checker through a combination of named pipes and spoofed client process IDs, thereby fooling the Workspace Updater Service into running arbitrary code as SYSTEM.

Coburn wrote in a [4]detailed blog post : "Whilst a low privilege account is required to perform the attack, environments that do not implement SMB signing are particularly vulnerable since an attack can be achieved without knowing valid credentials through NTLM credential relaying."

[5]Youtube Video

Turning that into full compromise of the Workspace client machine required some very lateral thinking about Microsoft's implementation of named pipes. Coburn wrote: "Another unique feature of pipes allows the server to impersonate the client user," adding that "quite often the server side of a named pipe is implemented within high privilege services."

PTP's Munro concluded: "The remote execution element of the vulnerability could have been avoided completely if the correct permissions were configured on the named pipe. The software update component is designed to run locally, so no remote connectivity is required for it to function." ®

Get our [6]Tech Resources



[1] https://nvd.nist.gov/vuln/detail/CVE-2020-8207

[2] https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes

[3] https://support.citrix.com/article/CTX277662

[4] https://www.pentestpartners.com/security-blog/raining-system-shells-with-citrix-workspace-app/

[5] https://www.youtube.com/watch?time_continue=3&v=Rlz-S5EkvcQ&feature=emb_logo

[6] https://whitepapers.theregister.com/

Include me out.