QID 379309

Date Published: 2024-02-15

QID 379309: Citrix Virtual Apps and Desktops Remote Code Execution (RCE) Vulnerability (CTX583930)

Citrix Virtual Apps and Desktops provides a virtualization solution for application and desktop delivery to any device, over any network.

Affected Versions:
The vulnerability affects the following supported versions of Windows Virtual Delivery Agent:
Citrix Virtual Apps and Desktops before 2311
Citrix Virtual Apps and Desktops 1912 LTSR before CU8 hotfix 19.12.8100.4
Citrix Virtual Apps and Desktops 2203 LTSR before CU4
QID Detection Logic (Authenticated)
This checks for vulnerable version of Citrix Virtual Apps and Desktops on Windows.

Successful exploitation of this vulnerability may result in an authenticated user being able to perform an RCE.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to CTX583930 for more information pertaining to this vulnerability.

    Vendor References

    CVEs related to QID 379309

    Software Advisories
    Advisory ID Software Component Link
    CTX583930 URL Logo support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184