Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.184
EPSS Ranking 95.0%