Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Xendesktop | — | Apply hotfix XD710ICAWSWX86005 for Citrix XenDesktop 7.1/7.5 (32-bit)Apply hotfix Rollup XD560VDAWX64400 (Version 5.6.400) for Citrix XenDesktop Virtual Desktop Agent Core
Services (64-bit)
Apply hotfix Rollup XD560VDAWX86400 (Version 5.6.400) for Citrix XenDesktop Virtual Desktop Agent Core
Services (32-bit)
Apply hotfix XD710ICAWSWX64005 for Citrix XenDesktop 7.1/7.5 (64-bit) | May 15, 2017 | Jul 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub