PT-2025-28651 · Citrix · Citrix Virtual Apps/Desktops
Published
2025-07-08
·
Updated
2025-08-06
·
CVE-2025-6759
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Virtual Delivery Agent for CVAD and Citrix DaaS versions prior to 2503
Windows Virtual Delivery Agent for CVAD and Citrix DaaS 2402 LTSR versions through CU2
2203 LTSR is not affected.
Description
A local privilege escalation issue exists in Windows Virtual Delivery Agent for CVAD and Citrix DaaS. This allows a low-privileged user to gain SYSTEM privileges. The issue stems from an open process handle with PROCESS ALL ACCESS rights within
GfxMgr.exe, running with SYSTEM privileges. This handle leaks into a child process, CtxGfx.exe, running with lower privileges. An attacker can duplicate this handle from CtxGfx.exe to create a new process with SYSTEM access.Recommendations
Windows Virtual Delivery Agent for CVAD and Citrix DaaS versions prior to 2503: Update to version 2503 or later.
Windows Virtual Delivery Agent for CVAD and Citrix DaaS 2402 LTSR versions through CU2: Apply the latest Cumulative Update (CU) available, ensuring it is newer than CU2.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Virtual Apps/Desktops