First published: Mon Nov 16 2020(Updated: )
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Virtual Apps and Desktops | <=2006 | |
Citrix Virtual Apps and Desktops | >=1903<=1912 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-8270.
The severity of CVE-2020-8270 is critical with a CVSS score of 8.8.
CVE-2020-8270 affects Citrix Virtual Apps and Desktops versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, and 7.15 LTSR CU6 hotfix CTX285341 and CTX285342.
CVE-2020-8270 allows an unprivileged Windows user on the VDA or an SMB user to perform arbitrary command execution as SYSTEM.
You can find more information about CVE-2020-8270 at the following link: [Citrix Support Article](https://support.citrix.com/article/CTX285059).