← back
CVE-2010-4566

CVE-2010-4566

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 28%
from disclosure to weapon0 days
Published on NVDJan 14
1st PoCDec 22
metasploitDec 21
exploitation probability
28%top 2% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.