CVE-2023-24483
Published on: Not Yet Published
Last Modified on: 02/24/2023 07:44:00 PM UTC
Certain versions of Virtual Apps And Desktops from Citrix contain the following vulnerability:
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
- CVE-2023-24483 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Citrix - Citrix Virtual Apps and Desktops version < 2212
- Affected Vendor/Software:
Citrix - Citrix Virtual Apps and Desktops version < 2203 LTSR before CU2
- Affected Vendor/Software:
Citrix - Citrix Virtual Apps and Desktops version < 1912 LTSR before CU6
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 | support.citrix.com text/html |
![]() |
Related QID Numbers
- 377988 Citrix Virtual Apps and Desktops Privilege Escalation Vulnerability (CTX477616)
Exploit/POC from Github
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level …
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Citrix | Virtual Apps And Desktops | All | All | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | - | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | cu1 | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | cu2 | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | cu3 | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | cu4 | All | All |
Application | Citrix | Virtual Apps And Desktops | 1912 | cu5 | All | All |
Application | Citrix | Virtual Apps And Desktops | 2203 | - | All | All |
Application | Citrix | Virtual Apps And Desktops | 2203 | cu1 | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:-:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:-:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu1:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu2:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu3:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu4:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu5:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:-:*:*:ltsr:*:*:*:
- cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:cu1:*:*:ltsr:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
#CitrixVirtualAppsandDesktops Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 support.citrix.com/article/CTX477… | 2023-02-14 16:09:35 |
![]() |
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 | support.citrix.com/article/CTX477… | 2023-02-14 16:17:59 |
![]() |
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 ift.tt/VTvumMz | 2023-02-14 16:18:36 |
![]() |
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483 support.citrix.com/article/CTX477… A vulnerability has… twitter.com/i/web/status/1… | 2023-02-14 17:43:02 |
![]() |
#Citrix published three security Bulletin's: 1) CVAD CVE-2023-24483 bit.ly/3YxEV1U 2) CWA for Windows CVE… twitter.com/i/web/status/1… | 2023-02-14 19:45:45 |
![]() |
Fletch Top Threat Alert: Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps - #CVE-2023-24483… twitter.com/i/web/status/1… | 2023-02-16 03:25:04 |
![]() |
Citrix Patches Multiple Vulnerabilities in Workspace, Virtual App, and Desktop (CVE-2023-24483, CVE-2023-24484, CVE… twitter.com/i/web/status/1… | 2023-02-16 15:35:05 |
![]() |
CVE-2023-24483 : A vulnerability has been identified that, if exploited, could result in a local user elevating the… twitter.com/i/web/status/1… | 2023-02-16 18:04:54 |
![]() |
The vulnerabilities addressed by Citrix are: •CVE-2023-24483: Improper privilege management flaw leading to privil… twitter.com/i/web/status/1… | 2023-02-16 19:22:00 |
![]() |
New vulnerabilities: CVE-2023-24484 & CVE-2023-24485 for Workspace before 2212, CVE-2023-24483 for VDA before 2212, LTSR 2203.2 or 1912.6 | 2023-02-15 08:39:25 |
![]() |
CVE-2023-24483 | 2023-02-16 18:38:44 |