Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151

Security Bulletin | Severity: High | Created: 09 Jul 2024 | Modified: 09 Jul 2024 | Status: Final

Applicable Products

  • Citrix Virtual Apps and Desktops

Description of Problem

A vulnerability has been identified that impacts Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS. Refer to below for further details: 

Affected Versions

The vulnerability affects the following supported versions of Windows Virtual Delivery Agent: 

Current Release (CR)

  • Citrix Virtual Apps and Desktops versions before 2402 

Long Term Service Release (LTSR)

  • Citrix Virtual Apps and Desktops 1912 LTSR before CU9
  • Citrix Virtual Apps and Desktops 2203 LTSR before CU5 

Summary

Windows Virtual Delivery Agent contains the vulnerability mentioned below 

CVE ID          DescriptionPre-requisites    CWECVSS
CVE-2024-6151Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesLocal access to the target systemCWE-269: Improper Privilege ManagementCVSS v4.0 Base Score: 8.5(CVS:4.0/AV:L/AV:L/AT:N/PR:L/UI:N/VCH/VI:H/VA:H/SC:N/S:N/S:N) 

What Customers Should Do

Citrix strongly recommends that customers upgrade their Windows Virtual Delivery Agent to versions that contain the fixes as soon as possible.  

Windows Virtual Delivery Agent versions that contain the fixes are: 

Current Release (CR)

  • Citrix Virtual Apps and Desktops 2402 and later versions 

Long Term Service Release (LTSR)

  • Citrix Virtual Apps and Desktops 1912 LTSR CU9 and later cumulative updates
  • Citrix Virtual Apps and Desktops 2203 LTSR CU5 and later cumulative updates
  • Citrix Virtual Apps and Desktops 2402 LTSR

Bleiben Sie immer aktuell informiert!

Wenn Sie sich in unsere Mailingliste eintragen, werden Sie zukünftig direkt informiert, sobald ein Alarm oder eine Information erstellt wird. Verpassen Sie keine sicherheitskritischen Meldungen mehr und abonnieren den Newsletter noch heute.

Invalid email address
Bitte wählen Sie Ihre Kategorie(n).
Citrix
Nutanix
Weitere
Wir versprechen, Sie nicht zuzuspammen. Sie können sich jederzeit wieder abmelden.