Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gateway_plug-in | Citrix | 12.0 (including) | 12.1-58 (including) |
Gateway_plug-in | Citrix | 13.0 (including) | 13.0-61.48 (including) |