CVE-2020-8270OS Command Injection in Citrix Virtual Apps AND Desktops

Severity
8.8HIGHNVD
EPSS
0.8%
top 25.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 24

Description

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5rfq-7599-rxw9: An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 h2022-05-24
VulnCheck
Citrix virtual_apps_and_desktops Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2020

📋Vendor Advisories

1
Citrix
Citrix Virtual Apps and Desktops Security Update2020-11-25