QID 377988

Date Published: 2023-06-28

QID 377988: Citrix Virtual Apps and Desktops Privilege Escalation Vulnerability (CTX477616)

Citrix Virtual Apps and Desktops provides a virtualization solution for application and desktop delivery to any device, over any network.

Citrix released a security advisory to address Privilege Escalation vulnerability in Virtual Apps and Desktops

Affected Versions:
Citrix Virtual Apps and Desktops versions before 2212
Citrix Virtual Apps and Desktops 2203 LTSR before CU2
Citrix Virtual Apps and Desktops 1912 LTSR before CU6

QID Detection Logic (Authenticated)
This checks for vulnerable version of Citrix Virtual Apps and Desktops on Windows.

Successful exploitation of this vulnerability could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to CTX477616 for more information pertaining to this vulnerability.

    Vendor References

    CVEs related to QID 377988

    Software Advisories
    Advisory ID Software Component Link
    CTX477616 URL Logo support.citrix.com/article/CTX477616