← Vulnerability feed

Vulnerability record · CVE-2008-0356 · published 18 January 2008

CVE-2008-0356: Citrix Presentation Server IMA Service Buffer Overflow

Citrix · Access Essentials

The Independent Management Architecture (IMA) service in Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 contains a buffer overflow triggered by an invalid size value in a packet sent to TCP port 2512 or 2513. Because the flaw is remotely reachable without authentication and yields full code execution, it is a serious pre-auth risk to exposed Citrix infrastructure.

10.0 CVSS 2.0 High EPSS 73% · top 0.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 base score of 10 and very high EPSS probability makes this a top remediation priority for any exposed Citrix deployment.

What it is

The Independent Management Architecture (IMA) service in Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 contains a buffer overflow triggered by an invalid size value in a packet sent to TCP port 2512 or 2513. Because the flaw is remotely reachable without authentication and yields full code execution, it is a serious pre-auth risk to exposed Citrix infrastructure.

Impact

A remote attacker can execute arbitrary code with the privileges of the IMA service, typically SYSTEM, leading to full compromise of the Citrix server. From there an attacker could pivot into the hosted desktop or application environment.

Attack surface

Reachable over the network via TCP ports 2512 and 2513; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing the IMA service to untrusted networks is in scope.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.72963, 99.4th percentile), indicating elevated likelihood of exploitation activity. References include a Zero Day Initiative advisory, suggesting coordinated disclosure of a working issue.

What to do

  • Apply the Citrix patch referenced in support article CTX114487 as the first action.
  • Restrict TCP ports 2512 and 2513 to trusted management networks using host and network firewalls.
  • Do not expose IMA service ports to the internet; place Citrix servers behind segmented network controls.
  • Upgrade or migrate off end-of-life versions (Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, Desktop Server 1.0) where feasible.
  • Monitor vendor advisories for any updated guidance on affected builds.

Detection

  • Alert on inbound connections to TCP 2512 and 2513 from untrusted or unexpected source networks.
  • Monitor IMA service process crashes or restarts, which can indicate malformed packet attempts.
  • Inspect network traffic to those ports for oversized or malformed size fields in IMA packets.
  • Correlate Citrix server logs with IDS/IPS signatures for buffer overflow attempts against the IMA service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0356 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2850Citrix access essentials vulnerabilityThe Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows…EPSS 2.8%7.5CVE-2009-2453Citrix presentation server permissions and access controls vulnerabilityCitrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…EPSS 1.4%7.5CVE-2006-5821Citrix metaframe vulnerabilityHeap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 …EPSS 5.2%7.2CVE-2008-3485Citrix metaframe presentation server permissions and access controls vulnerabilityUntrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed i…EPSS 0.35%7.2CVE-2007-0444Citrix metaframe memory buffer overflow vulnerabilityStack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and Meta…EPSS 14%6.8CVE-2008-4676Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti…EPSS 0.29%6.5CVE-2008-2300Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo…EPSS 1.4%6.5CVE-2006-3779Citrix metaframe vulnerabilityCitrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remot…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2008-0356), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.