VendorsCitrixvirtual_apps_and_desktopsall versions
Vulnerabilities

Citrix Virtual Apps

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-8270
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Published 2020-11-16 · Modified
9.0EPSS 0.035
CVE-2020-8269
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
Published 2020-11-16 · Modified
9.0EPSS 0.027
CVE-2020-8283
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.
Published 2020-12-14 · Modified
9.0EPSS 0.027
CVE-2024-6151
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Published 2024-07-10 · Analyzed
8.5EPSS 0.002
CVE-2023-24483
Privilege Escalation to NT AUTHORITY\SYSTEM on the vulnerable VDA
Published 2023-02-16 · Modified
7.8EPSS 0.003
CVE-2021-22928
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.
Published 2021-08-05 · Modified
7.8EPSS 0.002
CVE-2025-6759
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Published 2025-07-08 · Analyzed
7.8EPSS 0.002
CVE-2023-6184
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Published 2024-01-18 · Modified
7.2EPSS 0.466
CVE-2023-24490
Users with only access to launch VDA applications can launch an unauthorized desktop
Published 2023-07-10 · Modified
6.3EPSS 0.003