CVE-2024-6151Improper Privilege Management in Citrix Windows Virtual Delivery Agent

Severity
8.5HIGHNVD
EPSS
0.1%
top 68.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateJul 15

Description

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages6 packages

🔴Vulnerability Details

1
GHSA
GHSA-qcjc-4pgc-2w7h: Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps an2024-07-10

📋Vendor Advisories

2
Citrix
Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-61512024-07-15
Citrix
CVE-2024-6151: Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps an2024-07-10