Vulnerabilities > Citrix > Xenapp > 7.6

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2020-8283 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
network
low complexity
citrix CWE-269
critical
9.0
2020-11-16 CVE-2020-8269 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
network
low complexity
citrix CWE-269
critical
9.0
2016-06-01 CVE-2016-4810 Improper Access Control vulnerability in Citrix Xenapp and Xendesktop
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.
network
low complexity
citrix CWE-284
5.0