CVE-2023-24490
Citrix Virtual Delivery Agent (VDA) vulnerability analysis and mitigation

Overview

CVE-2023-24490 is a security vulnerability affecting Citrix Virtual Apps and Desktops (CVAD) and Virtual Delivery Agent (VDA) products. The vulnerability was discovered and initially recorded on January 24, 2023, affecting multiple versions of Citrix Virtual Apps and Desktops including 1912 LTSR and 2203 LTSR, as well as Linux Virtual Delivery Agent versions (CERT-FR, NVD).

Technical details

The vulnerability is classified as an improper access control issue (CWE-284) that allows users with only VDA application launch permissions to access unauthorized desktops. The severity assessment according to CVSS 3.1 varies between sources, with NVD rating it as MEDIUM (Base Score: 4.3) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N, while Citrix assessed it as MEDIUM (Base Score: 6.3) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L (NVD).

Impact

The vulnerability enables users to bypass intended access restrictions, potentially allowing them to launch desktop sessions they are not authorized to access. This represents a significant security policy bypass that could compromise the system's access control mechanisms (CERT-FR).

Mitigation and workarounds

Citrix has released security updates to address this vulnerability. For Citrix Virtual Apps and Desktops 1912 LTSR, users should apply CU7, for version 2203 LTSR, CU3 is required, and for Linux Virtual Delivery Agent 1912 LTSR, CU7 hotfix 1(19.12.7001) should be installed. Users running versions prior to 2305 should upgrade to the latest version (CERT-FR).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management