QID 376434

Date Published: 2022-04-26

QID 376434: Citrix XenDesktop Multiple Vulnerabilities(CTX319750)

Citrix XenDesktop is a virtual desktop infrastructure (VDI) product that allows full desktop virtualization, whereas XenApp is a software solution for Windows application virtualization

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM

Affected Versions
XenDesktop 7.15 LTSR CU7 and earlier versions of 7.15 LTSR QID Detection Logic (authenticated):
This QID checks for vulnerable versions of Citrix XenDesktop for Windows OS exe.

The vulnerability may allow an attacker to Execute unauthorized code or commands.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Please refer to CTX319750 for updates.
    Vendor References

    CVEs related to QID 376434

    Software Advisories
    Advisory ID Software Component Link
    CTX319750 URL Logo support.citrix.com/article/CTX319750