PT-2020-6866 · Citrix · Citrix Virtual Apps/Desktops
Published
2020-11-10
·
Updated
2020-12-03
·
CVE-2020-8270
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Citrix Virtual Apps and Desktops (CVAD) versions prior to 2009
Citrix Virtual Apps and Desktops (CVAD) versions 1912 LTSR CU1
Citrix Virtual Apps and Desktops (CVAD) versions 7.15 LTSR CU6
Description
The issue is related to the Citrix Virtual Apps and Desktops (CVAD) service, which allows an unprivileged Windows user or an SMB user to perform arbitrary command execution as SYSTEM. This is due to the failure to neutralize special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to elevate privileges and execute arbitrary commands.
Recommendations
For CVAD versions prior to 2009, apply hotfixes CTX285871 and CTX285872.
For CVAD versions 1912 LTSR CU1, apply hotfixes CTX285871 and CTX285872.
For CVAD versions 7.15 LTSR CU6, apply hotfixes CTX285341 and CTX285342.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Virtual Apps/Desktops