CVE-2025-6759
Citrix Virtual Delivery Agent (VDA) vulnerability analysis and mitigation

Overview

CVE-2025-6759 is a local privilege escalation vulnerability in the Windows Virtual Delivery Agent (VDA) for Citrix Virtual Apps and Desktops (CVAD) and Citrix DaaS that allows a low-privileged user to gain SYSTEM-level privileges. It was published on July 8, 2025, and assigned by Citrix. Affected versions include Current Release (CR) builds prior to 2503 and Long Term Service Release (LTSR) builds up to and including 2402 LTSR CU2. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (Feedly, Citrix Advisory CTX694820).

Technical details

The root cause is classified as CWE-269 (Improper Privilege Management), stemming from insufficient privilege controls within the Windows Virtual Delivery Agent component of Citrix CVAD and DaaS. An attacker with low-privileged local access can exploit this flaw without any user interaction to elevate their privileges to SYSTEM, the highest privilege level on Windows. The attack vector is local, requires low privileges, and has low attack complexity, making it straightforward to exploit once local access is obtained. A proof-of-concept (PoC) has been published on GitHub at https://github.com/olljanat/TestCitrixException, and a detailed technical write-up was published by Certitude Consulting (Certitude Blog, Feedly).

Impact

Successful exploitation grants a low-privileged local user full SYSTEM-level control over the affected Windows Virtual Delivery Agent host, compromising confidentiality, integrity, and availability of the system. An attacker could access sensitive data processed through the VDA, manipulate system configurations, install malware or backdoors, and potentially pivot to other systems within the virtual desktop infrastructure. Given that VDA hosts are central to Citrix virtual desktop environments, compromise of a single VDA could expose session data for multiple users and facilitate broader lateral movement within the enterprise (Feedly, Rapid7 Blog).

Exploitability

A public proof-of-concept exploit is available on GitHub (https://github.com/olljanat/TestCitrixException), lowering the barrier for exploitation. As of the time of disclosure, there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.015% (0.000150), indicating a currently low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Feedly, GitHub PoC).

Exploitation steps

  1. Reconnaissance: Identify systems running the Windows Virtual Delivery Agent for Citrix CVAD or DaaS, targeting versions prior to 2503 (CR) or 2402 LTSR CU2 and earlier (LTSR). Confirm local access to a low-privileged account on the target VDA host.
  2. Obtain local access: Authenticate to the target Windows VDA host using any low-privileged domain or local user account (e.g., a standard VDI session user).
  3. Deploy PoC: Use the publicly available proof-of-concept code from https://github.com/olljanat/TestCitrixException to trigger the improper privilege management flaw in the Citrix VDA component.
  4. Trigger privilege escalation: Execute the PoC tool, which exploits the improperly managed privileges within the VDA service or component to escalate the current user's context to SYSTEM.
  5. Achieve SYSTEM access: With SYSTEM privileges, the attacker can install software, modify system files, access all user session data on the VDA, disable security controls, or establish persistence for further lateral movement (Certitude Blog, GitHub PoC).

Indicators of compromise

  • Process: Unexpected processes running under the SYSTEM account spawned from a low-privileged user session context; unusual child processes of Citrix VDA services (e.g., picaSessionAgent.exe, BrokerAgent.exe) executing shells or administrative tools.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for non-administrative accounts; Event ID 4688 showing process creation with elevated tokens from standard user sessions.
  • File System: New files or executables dropped in system directories (e.g., C:\Windows\System32\) by non-administrative user accounts; unexpected scheduled tasks or services created under SYSTEM context.
  • Network: Outbound connections from VDA hosts to unknown external IPs initiated by processes running as SYSTEM that are not typical Citrix service traffic.
  • Registry: Modifications to HKLM registry keys (e.g., run keys, service configurations) by accounts that should not have write access (Certitude Blog, Feedly).

Mitigation and workarounds

Citrix has released patches documented in security advisory CTX694820. Organizations should upgrade to Citrix Virtual Apps and Desktops 2503 or later for Current Release (CR) deployments, and to 2402 LTSR CU3 or later for Long Term Service Release (LTSR) deployments. As interim mitigations, restrict local interactive and remote desktop access to VDA hosts to only authorized administrators, enforce least-privilege access controls, and monitor for suspicious privilege escalation activity. Given the public availability of PoC code, timely patching is strongly recommended (Citrix Advisory CTX694820, Rapid7 Blog).

Community reactions

Rapid7 published a blog post covering the vulnerability shortly after disclosure, highlighting the risk to Citrix virtual desktop environments and recommending immediate patching (Rapid7 Blog). Certitude Consulting published a detailed technical write-up explaining the root cause and exploitation mechanics (Certitude Blog). The Canadian Centre for Cyber Security (CCCS) issued an advisory (AV25-411) and HKCERT published a security bulletin covering the vulnerability (CCCS Advisory, HKCERT Bulletin). Security news outlets including GBHackers, SecurityOnline, and CyberSecurityNews covered the disclosure, and the vulnerability was discussed on Mastodon and Bluesky by security researchers.

Additional resources


SourceThis report was generated using AI

Related Citrix Virtual Delivery Agent (VDA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-6151HIGH8.5
  • Citrix Virtual Delivery Agent (VDA) logoCitrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
NoYesJul 10, 2024
CVE-2025-6759HIGH7.3
  • Citrix Virtual Delivery Agent (VDA) logoCitrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:ltsr:*:*:*
NoYesJul 08, 2025
CVE-2023-6184HIGH7.2
  • Citrix Virtual Delivery Agent (VDA) logoCitrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
NoYesJan 18, 2024
CVE-2024-8069MEDIUM5.1
  • Citrix Virtual Delivery Agent (VDA) logoCitrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:virtual_apps_and_desktops
YesYesNov 12, 2024
CVE-2024-8068MEDIUM5.1
  • Citrix Virtual Delivery Agent (VDA) logoCitrix Virtual Delivery Agent (VDA)
  • cpe:2.3:a:citrix:session_recording
YesYesNov 12, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management