QID 378693

QID 378693: Citrix Application Delivery Controller (ADC) and Citrix Gateway Privilege Escalation Vulnerability (CTX561480)

Citrix ADC and Citrix Gateway provides a virtualization solution for application and desktop delivery to any device, over any network.

Citrix released a security advisory to address Privilege Escalation vulnerability in Citrix ADC and Citrix Gateway

Affected Versions:
Citrix ADC and Citrix Gateway versions before 23.5.1.3

QID Detection Logic (Authenticated)
This checks for vulnerable version of Citrix ADC and Citrix Gateway on Windows.

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to CTX561480 for more information pertaining to this vulnerability.

    CVEs related to QID 378693

    Software Advisories
    Advisory ID Software Component Link
    CTX561480 URL Logo support.citrix.com/article/CTX561480/citrix-secure-access-client-for-windows-security-bulletin-for-cve202324491