Arbitrary Command Execution Vulnerability in Citrix Virtual Apps and Desktops
CVE-2020-8270
8.8HIGH
Key Information:
- Vendor
Citrix
- Vendor
- CVE Published:
- 16 November 2020
What is CVE-2020-8270?
An unprivileged Windows user or an SMB user on the Virtual Delivery Agent (VDA) may exploit this vulnerability to execute arbitrary commands with SYSTEM privileges on affected versions of Citrix Virtual Apps and Desktops, potentially leading to unauthorized access and control of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Citrix Virtual Apps and Desktops 2009, 1912 LTSRÂ CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved