Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Users with only access to launch VDA applications can launch an unauthorized desktop