CVE-2020-8269Improper Privilege Management in Citrix Xenapp

Severity
8.8HIGHNVD
EPSS
0.4%
top 41.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 24

Description

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages8 packages

NVDcitrix/xenapp7.77.15+3
NVDcitrix/xendesktop7.77.15+3
citrixcitrix/xenapp

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x9cq-5m73-v949: An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX28582022-05-24
VulnCheck
Citrix virtual_apps_and_desktops Improper Privilege Management2020

📋Vendor Advisories

1
Citrix
Citrix Virtual Apps and Desktops Security Update2020-11-25