
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6759 is a local privilege escalation vulnerability in the Windows Virtual Delivery Agent (VDA) for Citrix Virtual Apps and Desktops (CVAD) and Citrix DaaS that allows a low-privileged user to gain SYSTEM-level privileges. It was published on July 8, 2025, and assigned by Citrix. Affected versions include Current Release (CR) builds prior to 2503 and Long Term Service Release (LTSR) builds up to and including 2402 LTSR CU2. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (Feedly, Citrix Advisory CTX694820).
The root cause is classified as CWE-269 (Improper Privilege Management), stemming from insufficient privilege controls within the Windows Virtual Delivery Agent component of Citrix CVAD and DaaS. An attacker with low-privileged local access can exploit this flaw without any user interaction to elevate their privileges to SYSTEM, the highest privilege level on Windows. The attack vector is local, requires low privileges, and has low attack complexity, making it straightforward to exploit once local access is obtained. A proof-of-concept (PoC) has been published on GitHub at https://github.com/olljanat/TestCitrixException, and a detailed technical write-up was published by Certitude Consulting (Certitude Blog, Feedly).
Successful exploitation grants a low-privileged local user full SYSTEM-level control over the affected Windows Virtual Delivery Agent host, compromising confidentiality, integrity, and availability of the system. An attacker could access sensitive data processed through the VDA, manipulate system configurations, install malware or backdoors, and potentially pivot to other systems within the virtual desktop infrastructure. Given that VDA hosts are central to Citrix virtual desktop environments, compromise of a single VDA could expose session data for multiple users and facilitate broader lateral movement within the enterprise (Feedly, Rapid7 Blog).
A public proof-of-concept exploit is available on GitHub (https://github.com/olljanat/TestCitrixException), lowering the barrier for exploitation. As of the time of disclosure, there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.015% (0.000150), indicating a currently low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Feedly, GitHub PoC).
https://github.com/olljanat/TestCitrixException to trigger the improper privilege management flaw in the Citrix VDA component.picaSessionAgent.exe, BrokerAgent.exe) executing shells or administrative tools.C:\Windows\System32\) by non-administrative user accounts; unexpected scheduled tasks or services created under SYSTEM context.Citrix has released patches documented in security advisory CTX694820. Organizations should upgrade to Citrix Virtual Apps and Desktops 2503 or later for Current Release (CR) deployments, and to 2402 LTSR CU3 or later for Long Term Service Release (LTSR) deployments. As interim mitigations, restrict local interactive and remote desktop access to VDA hosts to only authorized administrators, enforce least-privilege access controls, and monitor for suspicious privilege escalation activity. Given the public availability of PoC code, timely patching is strongly recommended (Citrix Advisory CTX694820, Rapid7 Blog).
Rapid7 published a blog post covering the vulnerability shortly after disclosure, highlighting the risk to Citrix virtual desktop environments and recommending immediate patching (Rapid7 Blog). Certitude Consulting published a detailed technical write-up explaining the root cause and exploitation mechanics (Certitude Blog). The Canadian Centre for Cyber Security (CCCS) issued an advisory (AV25-411) and HKCERT published a security bulletin covering the vulnerability (CCCS Advisory, HKCERT Bulletin). Security news outlets including GBHackers, SecurityOnline, and CyberSecurityNews covered the disclosure, and the vulnerability was discussed on Mastodon and Bluesky by security researchers.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."