CVE Vulnerabilities

CVE-2021-22928

Published: Aug 05, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

Affected Software

NameVendorStart VersionEnd Version
Virtual_apps_and_desktopsCitrix2006 (including)2106 (including)
Virtual_apps_and_desktopsCitrix1912 (including)1912 (including)
Virtual_apps_and_desktopsCitrix1912-cu3 (including)1912-cu3 (including)
XenappCitrix7.15 (including)7.15 (including)
XenappCitrix7.15-cu6 (including)7.15-cu6 (including)
XenappCitrix7.15-cu7 (including)7.15-cu7 (including)
XendesktopCitrix7.15 (including)7.15 (including)
XendesktopCitrix7.15-cu6 (including)7.15-cu6 (including)
XendesktopCitrix7.15-cu7 (including)7.15-cu7 (including)

References