CVE-2014-4700
Summary
| CVE | CVE-2014-4700 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-11 14:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:A/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Citrix | Xendesktop | 4.0 | All | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp1 | All | All |
| Application | Citrix | Xendesktop | 4.0 | fp2 | All | All |
| Application | Citrix | Xendesktop | 5.6 | fp1 | All | All |
| Application | Citrix | Xendesktop | All | All | All | All |
| Application | Citrix | Xendesktop | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Vulnerability in Citrix XenDesktop could result in unauthorized access to another user's desktop | af854a3a-2127-422b-91ae-364da2661108 | support.citrix.com | Patch, Vendor Advisory |
| Citrix XenDesktop CVE-2014-4700 Unspecified Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Citrix XenDesktop Unspecified Flaw in Pooled Random Desktop Groups Lets Remote Users Access Other User Desktops - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.