Citrix Vulnerabilities and Affected Products
Vulnerabilities associated with virtual_apps_and_desktops.
Products
Clear product- NetScaler ADC and NetScaler Gateway15 vulnerabilities
- SD-WAN and NetScaler7 vulnerabilities
- Citrix Workspace app for Windows5 vulnerabilities
- virtual_apps_and_desktops5 vulnerabilities
- Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance4 vulnerabilities
- Citrix Gateway, Citrix ADC4 vulnerabilities
- NetScaler ADC4 vulnerabilities
- NetScaler Gateway4 vulnerabilities
- ShareFile4 vulnerabilities
- application_delivery_controller_firmware2 vulnerabilities
- Citrix ADC and Citrix Gateway2 vulnerabilities
- Citrix Application Delivery Management (Citrix ADM)2 vulnerabilities
- Citrix Secure Access Client for Windows2 vulnerabilities
- Citrix Workspace app for HTML52 vulnerabilities
- NetScaler2 vulnerabilities
- NetScaler ADC and Gateway2 vulnerabilities
- netscaler_application_delivery_controller2 vulnerabilities
- netscaler_gateway2 vulnerabilities
- Secure Access Client for Mac2 vulnerabilities
- Secure Access Client for Windows2 vulnerabilities
- secure_access_client2 vulnerabilities
- Session Recording2 vulnerabilities
- workspace_app2 vulnerabilities
- Application Delivery Controller (ADC) and Gateway1 vulnerability
- Citrix Endpoint Analysis Client for Windows1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-6151HIGH | Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS CWE-269Jul 10, 2024 | CVSS8.5v4.0 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6184MEDIUM | Citrix virtual_apps_and_desktops Improper Control of Dynamically-Managed Code ResourcesCross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | CVSS5.0v3.1 | EPSS46.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-8283HIGH | Citrix virtual_apps_and_desktops Improper Privilege ManagementAn authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9. CWE-269Dec 14, 2020 | CVSS8.8v3.1 | EPSS2.57% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-8270HIGH | Citrix virtual_apps_and_desktops Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342 CWE-78Nov 16, 2020 | CVSS8.8v3.1 | EPSS3.48% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-8269HIGH | Citrix virtual_apps_and_desktops Improper Privilege ManagementAn unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 CWE-269Nov 16, 2020 | CVSS8.8v3.1 | EPSS2.68% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |