PT-2016-7656 · Citrix · Citrix Receiver Desktop Lock
Rithwik Jayasimha
·
Published
2016-11-07
·
Updated
2017-09-06
·
CVE-2016-9111
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Citrix Receiver Desktop Lock version 4.5
Description
The issue concerns incorrect access control mechanisms, potentially allowing an attacker to bypass authentication requirements. This could be achieved by leveraging physical access to a Virtual Desktop Infrastructure (VDI) and temporarily disconnecting a LAN cable. It's noted that the vendor was unable to reproduce the issue despite extensive investigation.
Recommendations
For Citrix Receiver Desktop Lock version 4.5, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Citrix Receiver Desktop Lock