HIGH
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Published Jul 10, 2024
8.5
HIGHCVSS 4.0
EPSS 0.21%
Description
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
Affected products
-
- Version 1912 LTSRStatusaffectedConstraints<CU9
- Version 2203 LTSRStatusaffectedConstraints<CU5
- Version 2402StatusaffectedConstraints<0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Citrix | Windows Virtual Delivery Agent | unaffected |
|
OR
- ≤ 2311
- 1912
- 1912
- 1912
- 1912
- 1912
- 1912
- 1912
- 1912
- 1912
- 2203
- 2203
- 2203
- 2203
- 2203
-
- Version 0StatusaffectedConstraints<2402
- Version 1912 LTSRStatusaffectedConstraints<CU9
- Version 2203 LTSRStatusaffectedConstraints<CU5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Citrix | Virtual Apps and Desktops | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47295 Advisory
- https://support.citrix.com/article/CTX678035 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47295 | Advisory | |
| https://support.citrix.com/article/CTX678035 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Citrix
Published Jul 10, 2024
Updated Aug 1, 2024
Reserved Jun 18, 2024
Link CVE-2024-6151
CISA Vulnrichment
Updated Jul 12, 2024
ENISA EUVD
EUVD-2024-47295 Assigner Citrix
Published Jul 10, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-47295