Threat Advisory

Citrix Vulnerabilities Exploit MSMQ and BinaryFormatter for RCE

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have identified vulnerabilities in Citrix Virtual Apps and Desktop that could lead to unauthorized remote code execution, leveraging insecure permissions in the Session Recording component. The flaws exploit a misconfigured Microsoft Message Queuing (MSMQ) instance and the BinaryFormatter deserialization process, which is unsafe with untrusted input. Successful exploitation requires authenticated access within the same Active Directory domain and intranet as the session recording server. Researchers highlight the potential for significant exploitation risks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have identified vulnerabilities in Citrix Virtual Apps and Desktop that could lead to unauthorized remote code execution, leveraging insecure permissions in the Session Recording component. The flaws exploit a misconfigured Microsoft Message Queuing (MSMQ) instance and the BinaryFormatter deserialization process, which is unsafe with untrusted input. Successful exploitation requires authenticated access within the same Active Directory domain and intranet as the session recording server. Researchers highlight the potential for significant exploitation risks.[emaillocker id="1283"]

 

  • CVE-2024-8068: This vulnerability, with a CVSS score of 5.1, allows attackers to escalate privileges to the NetworkService Account, posing a medium-severity threat.

 

  • CVE-2024-8069: Rated 5.1 on the CVSS scale, this flaw enables limited remote code execution with NetworkService Account privileges, increasing the risk of exploitation.

 

The identified vulnerabilities in Citrix Virtual Apps and Desktop highlight the risks of insecure deserialization and misconfigured permissions. Prompt updates to patched versions are essential to mitigate potential exploitation.

RECOMMENDATION:

We strongly recommend you update Citrix Virtual Apps and Desktop to below versions:

 

  • Citrix Session Recording 2407 hotfix 24.5.200.8

Download from here: https://support.citrix.com/article/CTX692047

  • Citrix Session Recording 1912 LTSR CU9 hotfix 19.12.9100.6

Download from here:  https://support.citrix.com/article/CTX692044

  • Citrix Session Recording 2203 LTSR CU5 hotfix 22.03.5100.11

Download from here:  https://support.citrix.com/article/CTX692045

  • Citrix Session Recording 2402 LTSR CU1 hotfix 24.02.1200.16

Download from here:  https://support.citrix.com/article/CTX692046

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

[/emaillocker]
crossmenu