CVE-2023-24483

Published on: Not Yet Published

Last Modified on: 02/24/2023 07:44:00 PM UTC

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of Virtual Apps And Desktops from Citrix contain the following vulnerability:

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

  • CVE-2023-24483 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.
  • Affected Vendor/Software: URL Logo Citrix - Citrix Virtual Apps and Desktops version < 2212
  • Affected Vendor/Software: URL Logo Citrix - Citrix Virtual Apps and Desktops version < 2203 LTSR before CU2
  • Affected Vendor/Software: URL Logo Citrix - Citrix Virtual Apps and Desktops version < 1912 LTSR before CU6

CVSS3 Score: 7.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVE References

Description Tags Link
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 support.citrix.com
text/html
URL Logo MISC support.citrix.com/article/CTX477616/citrix-virtual-apps-and-desktops-security-bulletin-for-cve202324483

Related QID Numbers

  • 377988 Citrix Virtual Apps and Desktops Privilege Escalation Vulnerability (CTX477616)

Exploit/POC from Github

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level …

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCitrixVirtual Apps And DesktopsAllAllAllAll
ApplicationCitrixVirtual Apps And Desktops1912-AllAll
ApplicationCitrixVirtual Apps And Desktops1912cu1AllAll
ApplicationCitrixVirtual Apps And Desktops1912cu2AllAll
ApplicationCitrixVirtual Apps And Desktops1912cu3AllAll
ApplicationCitrixVirtual Apps And Desktops1912cu4AllAll
ApplicationCitrixVirtual Apps And Desktops1912cu5AllAll
ApplicationCitrixVirtual Apps And Desktops2203-AllAll
ApplicationCitrixVirtual Apps And Desktops2203cu1AllAll
Operating
System
MicrosoftWindows-AllAllAll
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:-:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:-:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu1:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu2:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu3:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu4:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu5:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:-:*:*:ltsr:*:*:*:
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:cu1:*:*:ltsr:*:*:*:
  • cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @ComputerPunks #CitrixVirtualAppsandDesktops Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 support.citrix.com/article/CTX477… 2023-02-14 16:09:35
Twitter Icon @ThomasPreischl Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 | support.citrix.com/article/CTX477… 2023-02-14 16:17:59
Twitter Icon @michael_elsner Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 ift.tt/VTvumMz 2023-02-14 16:18:36
Twitter Icon @stevegreenberg Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 support.citrix.com/article/CTX477… A vulnerability has… twitter.com/i/web/status/1… 2023-02-14 17:43:02
Twitter Icon @vdNieuwenhofEU #Citrix published three security Bulletin's: 1) CVAD CVE-2023-24483 bit.ly/3YxEV1U 2) CWA for Windows CVE… twitter.com/i/web/status/1… 2023-02-14 19:45:45
Twitter Icon @fletch_ai Fletch Top Threat Alert: Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps - #CVE-2023-24483… twitter.com/i/web/status/1… 2023-02-16 03:25:04
Twitter Icon @qualys Citrix Patches Multiple Vulnerabilities in Workspace, Virtual App, and Desktop (CVE-2023-24483, CVE-2023-24484, CVE… twitter.com/i/web/status/1… 2023-02-16 15:35:05
Twitter Icon @CVEreport CVE-2023-24483 : A vulnerability has been identified that, if exploited, could result in a local user elevating the… twitter.com/i/web/status/1… 2023-02-16 18:04:54
Twitter Icon @xyberpwn The vulnerabilities addressed by Citrix are: •CVE-2023-24483: Improper privilege management flaw leading to privil… twitter.com/i/web/status/1… 2023-02-16 19:22:00
Reddit Logo Icon /r/Citrix New vulnerabilities: CVE-2023-24484 & CVE-2023-24485 for Workspace before 2212, CVE-2023-24483 for VDA before 2212, LTSR 2203.2 or 1912.6 2023-02-15 08:39:25
Reddit Logo Icon /r/netcve CVE-2023-24483 2023-02-16 18:38:44
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report