PT-2016-7656 · Citrix · Citrix Receiver Desktop Lock

Rithwik Jayasimha

·

Published

2016-11-07

·

Updated

2017-09-06

·

CVE-2016-9111

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix Receiver Desktop Lock version 4.5
Description The issue concerns incorrect access control mechanisms, potentially allowing an attacker to bypass authentication requirements. This could be achieved by leveraging physical access to a Virtual Desktop Infrastructure (VDI) and temporarily disconnecting a LAN cable. It's noted that the vendor was unable to reproduce the issue despite extensive investigation.
Recommendations For Citrix Receiver Desktop Lock version 4.5, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9111

Affected Products

Citrix Receiver Desktop Lock