Vulnerabilities > Citrix > Xendesktop

DATE CVE VULNERABILITY TITLE RISK
2021-08-05 CVE-2021-22928 Unspecified vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.
local
low complexity
citrix
7.2
2020-12-14 CVE-2020-8283 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
network
low complexity
citrix CWE-269
critical
9.0
2020-11-16 CVE-2020-8269 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops, Xenapp and Xendesktop
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
network
low complexity
citrix CWE-269
critical
9.0
2016-08-19 CVE-2016-6493 7PK - Security Features vulnerability in Citrix Xenapp and Xendesktop
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.
network
low complexity
citrix CWE-254
7.5
2016-06-01 CVE-2016-4810 Improper Access Control vulnerability in Citrix Xenapp and Xendesktop
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.
network
low complexity
citrix CWE-284
5.0
2014-07-11 CVE-2014-4700 Permissions, Privileges, and Access Controls vulnerability in Citrix Xendesktop
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
4.9
2013-11-05 CVE-2013-6077 Permissions, Privileges, and Access Controls vulnerability in Citrix Xendesktop 7.0
Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.
network
citrix CWE-264
5.8
2012-12-26 CVE-2012-6314 Local Security Bypass vulnerability in Citrix Xendesktop 5.6
Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.
network
low complexity
citrix
5.0