QID 379056

Date Published: 2024-01-24

QID 379056: Citrix Virtual Apps and Desktops Improper Access Control Vulnerability (CTX559370)

Citrix Virtual Apps and Desktops provides a virtualization solution for application and desktop delivery to any device, over any network.

Note: Customers are recommended only to upgrade their Windows and Linux Virtual Delivery Agents to address this vulnerability. Affected Versions:
The vulnerability affects the following supported versions of Windows Virtual Delivery Agent:
Citrix Virtual Apps and Desktops versions before 2305
Citrix Virtual Apps and Desktops 2203 LTSR before CU3
Citrix Virtual Apps and Desktops 1912 LTSR before CU7
The vulnerability affects the following supported versions of Linux Virtual Delivery Agent:
Linux Virtual Delivery Agent versions before 2305
Linux Virtual Delivery Agent 2203 LTSR before CU3
Linux Virtual Delivery Agent 1912 LTSR before CU7 hotfix 1(19.12.7001)
QID Detection Logic (Authenticated)
This checks for vulnerable version of Citrix Virtual Apps and Desktops on Windows.

Successful exploitation of this vulnerability could impacts Virtual Delivery Agents for Windows or Linux used by Citrix Virtual Apps and Desktops and Citrix DaaS.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to CTX559370 for more information pertaining to this vulnerability.

    Vendor References

    CVEs related to QID 379056

    Software Advisories
    Advisory ID Software Component Link
    CTX559370 URL Logo support.citrix.com/article/CTX559370