7.8

CVE-2021-22928

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Virtual Apps And Desktops SwEdition - Version >= 2006 <= 2106
Citrix ≫ Virtual Apps And Desktops Version 1912 Update - SwEdition ltsr
Citrix ≫ Virtual Apps And Desktops Version 1912 Update cu3
Citrix ≫ Xenapp Version 7.15 Update - SwEdition ltsr
Citrix ≫ Xenapp Version 7.15 Update cu6 SwEdition ltsr
Citrix ≫ Xenapp Version 7.15 Update cu7 SwEdition ltsr
Citrix ≫ Xendesktop Version 7.15 Update - SwEdition ltsr
Citrix ≫ Xendesktop Version 7.15 Update cu6 SwEdition ltsr
Citrix ≫ Xendesktop Version 7.15 Update cu7 SwEdition ltsr
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.158
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.citrix.com/article/CTX319750
Patch
Vendor Advisory