CVE-2014-4700
Summary
| CVE | CVE-2014-4700 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-11 14:55:00 UTC |
| Updated | 2018-12-18 14:42:00 UTC |
| Description | Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Xendesktop | 4.0 | All | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp1 | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp2 | All | All |
| Application | Citrix | Xendesktop | 5.6 | fp1 | All | All |
| Application | Citrix | Xendesktop | 4.0 | All | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp1 | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp2 | All | All |
| Application | Citrix | Xendesktop | 5.6 | fp1 | All | All |
| Application | Citrix | Xendesktop | All | All | All | All |
| Application | Citrix | Xendesktop | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | SECUNIA | secunia.com | Third Party Advisory |
| Citrix XenDesktop Unspecified Flaw in Pooled Random Desktop Groups Lets Remote Users Access Other User Desktops - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Citrix XenDesktop CVE-2014-4700 Unspecified Unauthorized Access Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerability in Citrix XenDesktop could result in unauthorized access to another user's desktop | CONFIRM | support.citrix.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.