CVE-2016-4810: High severity citrix vulnerability
Published Jun 1, 2016
·Updated
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.
Affected Software
10 affected components
Citrix XenApp=7.5
Citrix XenApp=7.6
Citrix XenDesktop=7.0
Citrix XenDesktop=7.1
Citrix XenDesktop=7.5
Citrix XenDesktop=7.6
Citrix XenDesktop=7.6-fp1
Citrix XenDesktop=7.6-fp2
Citrix XenDesktop=7.6-fp3
Citrix XenDesktop=7.6-ltsr
Event History
Jun 1, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4810?
CVE-2016-4810 has a medium severity level, allowing unauthorized modifications to Access Policy rules.
2
How do I fix CVE-2016-4810?
To fix CVE-2016-4810, upgrade to Citrix XenDesktop 7.6 LTSR Cumulative Update 1 or later.
3
Which versions of Citrix are affected by CVE-2016-4810?
CVE-2016-4810 affects Citrix XenDesktop versions 7.0, 7.1, 7.5, and 7.6, as well as XenApp versions 7.5 and 7.6.
4
What types of attacks does CVE-2016-4810 facilitate?
CVE-2016-4810 enables attackers to set Access Policy rules on the XenDesktop Delivery Controller.
5
Is there a workaround for CVE-2016-4810?
There are no known workarounds for CVE-2016-4810; patching is the recommended solution.