← Vulnerability feed

Vulnerability record · CVE-2008-5107 · published 17 November 2008

CVE-2008-5107: Citrix desktop server information exposure vulnerability

Citrix · Desktop Server

The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.

1.9 CVSS 2.0 Low EPSS 0.30% · top 80.0% CWE-200 · Information exposure
1.9CVSS 2.0 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.

AV:L/AC:M/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5107 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0356Citrix Presentation Server IMA Service Buffer OverflowThe Independent Management Architecture (IMA) service in Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop S…EPSS 73%analysed7.5CVE-2009-2453Citrix presentation server permissions and access controls vulnerabilityCitrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…EPSS 1.4%6.8CVE-2008-4676Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti…EPSS 0.29%6.5CVE-2008-2300Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo…EPSS 1.4%6.5CVE-2006-3779Citrix metaframe vulnerabilityCitrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remot…EPSS 1.3%5.0CVE-2008-2299Citrix presentation server vulnerabilityUnspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and…EPSS 1.1%4.3CVE-2002-2426Citrix access essentials cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1…EPSS 0.66%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2008-5107), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.