CVE-2022-21827
published 2022-05-26CVE-2022-21827: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an…
PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.17%
7.0th percentile
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adc | — | — |
| citrix | citrix_gateway | — | — |
| citrix | gateway_plug-in | < 21.9.1.2 | 21.9.1.2 |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.6MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2022-21827: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could
vendor_citrix·2022-05-26·CVSS 7.1
CVE-2022-21827 [HIGH] CWE-269 CVE-2022-21827: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could
CVE-2022-21827: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
Citrix
Citrix Gateway Plug-in for Windows Security Bulletin for CVE-2022-21827
vendor_citrix·CVSS 7.1
CVE-2022-21827 [HIGH] CWE-284 Citrix Gateway Plug-in for Windows Security Bulletin for CVE-2022-21827
Citrix Gateway Plug-in for Windows Security Bulletin for CVE-2022-21827
CWE Pre-conditions CVE-2022-21827 Arbitrary corruption or deletion of files as SYSTEM CWE-284: Improper Access Control Local access to a machine that has the vulnerable plug-in installed The following supported versions of Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) are affected by this vulnerability: Citrix Gateway Plug-in for Windows versions before 21.9.1.2 Instructions This issue has been addressed in the following versions of Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows): Citrix Gateway Plug-in for Windows version 21.9.1.2 and later releases Citrix recommends that affected customers upgrade the Citrix Gateway Plug-in installed on their endpoints by taking the foll
GHSA
GHSA-h578-jrpj-wc47: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21
ghsa_unreviewed·2022-05-27
CVE-2022-21827 [HIGH] CWE-269 GHSA-h578-jrpj-wc47: An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-26
Published