CVE Vulnerabilities

CVE-2021-22928

Published: Aug 05, 2021 | Modified: Jul 12, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

Affected Software

Name Vendor Start Version End Version
Virtual_apps_and_desktops Citrix 2006 (including) 2106 (including)
Virtual_apps_and_desktops Citrix 1912 (including) 1912 (including)
Virtual_apps_and_desktops Citrix 1912-cu3 (including) 1912-cu3 (including)
Xenapp Citrix 7.15 (including) 7.15 (including)
Xenapp Citrix 7.15-cu6 (including) 7.15-cu6 (including)
Xenapp Citrix 7.15-cu7 (including) 7.15-cu7 (including)
Xendesktop Citrix 7.15 (including) 7.15 (including)
Xendesktop Citrix 7.15-cu6 (including) 7.15-cu6 (including)
Xendesktop Citrix 7.15-cu7 (including) 7.15-cu7 (including)

References