CVE-2020-8270: OS Command Injection
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2020-8270.
What is the severity of CVE-2020-8270?
The severity of CVE-2020-8270 is critical with a CVSS score of 8.8.
Which software versions are affected by CVE-2020-8270?
CVE-2020-8270 affects Citrix Virtual Apps and Desktops versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, and 7.15 LTSR CU6 hotfix CTX285341 and CTX285342.
What is the impact of CVE-2020-8270?
CVE-2020-8270 allows an unprivileged Windows user on the VDA or an SMB user to perform arbitrary command execution as SYSTEM.
Where can I find more information about CVE-2020-8270?
You can find more information about CVE-2020-8270 at the following link: [Citrix Support Article](https://support.citrix.com/article/CTX285059).