CVE-2014-4700: Medium severity citrix virtual apps and desktops vulnerability
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4700?
CVE-2014-4700 is classified as a high severity vulnerability due to the potential for unauthorized access to user desktops.
How do I fix CVE-2014-4700?
To fix CVE-2014-4700, ensure that the ShutdownDesktopsAfterUse setting is enabled in your Citrix XenDesktop configuration.
Which versions of Citrix XenDesktop are affected by CVE-2014-4700?
CVE-2014-4700 affects Citrix XenDesktop versions 4.x, 5.x, and 7.x prior to version 7.11.
What happens if CVE-2014-4700 is exploited?
If exploited, CVE-2014-4700 allows malicious local guest users to gain unauthorized access to another user's desktop.
Is there a workaround for CVE-2014-4700?
A temporary workaround for CVE-2014-4700 is to restrict local guest access until a permanent fix can be applied.