Arbitrary Command Execution Vulnerability in Citrix Universal Print Server
CVE-2020-8283
8.8HIGH
Key Information:
- Vendor
- Citrix
- Vendor
- CVE Published:
- 14 December 2020
Summary
An authorized user on a Windows host running Citrix Universal Print Server can execute arbitrary commands with SYSTEM privileges. This vulnerability affects various versions of Citrix Virtual Apps and Desktops (CVAD), specifically those prior to the hotfix releases CTX285870, CTX286120, and CTX285344. Administrators should review and apply the appropriate updates to mitigate potential security risks.
Affected Version(s)
Citrix Virtual Apps and Desktops 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved