Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2023-02-16 CVE-2023-24483 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
local
low complexity
citrix CWE-269
7.8
2023-02-16 CVE-2023-24484 Unspecified vulnerability in Citrix Workspace 1912/2105/2203.1
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
local
low complexity
citrix
5.5
2023-02-16 CVE-2023-24485 Incorrect Authorization vulnerability in Citrix Workspace 1912/2105/2203.1
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
local
low complexity
citrix CWE-863
7.8
2023-01-26 CVE-2022-27507 Resource Exhaustion vulnerability in Citrix Application Delivery Controller and Gateway
Authenticated denial of service
network
low complexity
citrix CWE-400
6.5
2023-01-26 CVE-2022-27508 Resource Exhaustion vulnerability in Citrix Application Delivery Controller and Gateway
Unauthenticated denial of service
network
low complexity
citrix CWE-400
7.5
2022-12-13 CVE-2022-27518 Unspecified vulnerability in Citrix products
Unauthenticated remote arbitrary code execution
network
low complexity
citrix
critical
9.8
2022-11-08 CVE-2022-27510 Improper Authentication vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Unauthorized access to Gateway user capabilities
network
low complexity
citrix CWE-287
critical
9.8
2022-11-08 CVE-2022-27513 Insufficient Verification of Data Authenticity vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Remote desktop takeover via phishing
network
low complexity
citrix CWE-345
critical
9.6
2022-11-08 CVE-2022-27516 Improper Restriction of Excessive Authentication Attempts vulnerability in Citrix Application Delivery Controller Firmware and Gateway
User login brute force protection functionality bypass
network
low complexity
citrix CWE-307
critical
9.8
2022-06-16 CVE-2022-27511 Unspecified vulnerability in Citrix Application Delivery Management
Corruption of the system by a remote, unauthenticated user.
network
high complexity
citrix
8.1