EXECUTIVE SUMMARY:
Researchers have identified vulnerabilities in Citrix Virtual Apps and Desktop that could lead to unauthorized remote code execution, leveraging insecure permissions in the Session Recording component. The flaws exploit a misconfigured Microsoft Message Queuing (MSMQ) instance and the BinaryFormatter deserialization process, which is unsafe with untrusted input. Successful exploitation requires authenticated access within the same Active Directory domain and intranet as the session recording server. Researchers highlight the potential for significant exploitation risks.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have identified vulnerabilities in Citrix Virtual Apps and Desktop that could lead to unauthorized remote code execution, leveraging insecure permissions in the Session Recording component. The flaws exploit a misconfigured Microsoft Message Queuing (MSMQ) instance and the BinaryFormatter deserialization process, which is unsafe with untrusted input. Successful exploitation requires authenticated access within the same Active Directory domain and intranet as the session recording server. Researchers highlight the potential for significant exploitation risks.[emaillocker id="1283"]
The identified vulnerabilities in Citrix Virtual Apps and Desktop highlight the risks of insecure deserialization and misconfigured permissions. Prompt updates to patched versions are essential to mitigate potential exploitation.
RECOMMENDATION:
We strongly recommend you update Citrix Virtual Apps and Desktop to below versions:
Download from here: https://support.citrix.com/article/CTX692047
Download from here: https://support.citrix.com/article/CTX692044
Download from here: https://support.citrix.com/article/CTX692045
Download from here: https://support.citrix.com/article/CTX692046
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html