#VU100448 Improper privilege management in Citrix Virtual Apps and Desktops - CVE-2024-8068


Vulnerability identifier: #VU100448

Vulnerability risk: Medium

CVSSv4.0: 1.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2024-8068

CWE-ID: CWE-269

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
Citrix Virtual Apps and Desktops
Other software / Other software solutions

Vendor: Citrix

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper privilege management within the NetworkService Account access. A remote user can escalate privileges on the system.

Note, an attacker must be authenticated in the same Windows Active Directory domain as the session recording server domain.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Citrix Virtual Apps and Desktops: before 1912


External links
https://support.citrix.com/article/CTX691941


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability