Citrix Products Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.
Note:
Proof of concept exploit for CVE-2024-8068 and CVE-2024-8069 exists on the internet. Attacker needs to be authenticated before exploiting the vulunbilities. Hence, the overall risk is rated as Medium Risk.
Impact
- Remote Code Execution
- Elevation of Privilege
- Denial of Service
System / Technologies affected
- Citrix Virtual Apps and Desktops before 2407 hotfix 24.5.200.8
- Citrix Virtual Apps and Desktops 1912 LTSR before CU9 hotfix 19.12.9100.6
- Citrix Virtual Apps and Desktops 2203 LTSR before CU5 hotfix 22.03.5100.11
- Citrix Virtual Apps and Desktops 2402 LTSR before CU1 hotfix 24.02.1200.16
- NetScaler ADC and NetScaler Gateway 14.1 before 14.1-29.72
- NetScaler ADC and NetScaler Gateway 13.1 before 13.1-55.34
- NetScaler ADC 13.1-FIPS before 13.1-37.207
- NetScaler ADC 12.1-FIPS before 12.1-55.321
- NetScaler ADC 12.1-NDcPP before 12.1-55.321
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US
- https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US
Vulnerability Identifier
Source
Related Link
- https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US
- https://support.citrix.com/s/article/CTX691608-netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20248534-and-cve20248535?language=en_US
- https://labs.watchtowr.com/visionaries-at-citrix-have-democratised-remote-network-access-citrix-virtual-apps-and-desktops-cve-unknown/
- https://github.com/watchtowrlabs/Citrix-Virtual-Apps-XEN-Exploit
Share with