PT-2020-6866 · Citrix · Citrix Virtual Apps/Desktops

Published

2020-11-10

·

Updated

2020-12-03

·

CVE-2020-8270

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Citrix Virtual Apps and Desktops (CVAD) versions prior to 2009 Citrix Virtual Apps and Desktops (CVAD) versions 1912 LTSR CU1 Citrix Virtual Apps and Desktops (CVAD) versions 7.15 LTSR CU6
Description The issue is related to the Citrix Virtual Apps and Desktops (CVAD) service, which allows an unprivileged Windows user or an SMB user to perform arbitrary command execution as SYSTEM. This is due to the failure to neutralize special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to elevate privileges and execute arbitrary commands.
Recommendations For CVAD versions prior to 2009, apply hotfixes CTX285871 and CTX285872. For CVAD versions 1912 LTSR CU1, apply hotfixes CTX285871 and CTX285872. For CVAD versions 7.15 LTSR CU6, apply hotfixes CTX285341 and CTX285342.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02424
CVE-2020-8270

Affected Products

Citrix Virtual Apps/Desktops