8.5

CVE-2024-6151

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CitrixVirtual Apps And Desktops SwEdition- Version <= 2311
CitrixVirtual Apps And Desktops Version1912 Update- SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu1 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu2 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu3 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu4 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu5 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu6 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu7 SwEditionltsr
CitrixVirtual Apps And Desktops Version1912 Updatecu8 SwEditionltsr
CitrixVirtual Apps And Desktops Version2203 Update- SwEditionltsr
CitrixVirtual Apps And Desktops Version2203 Updatecu1 SwEditionltsr
CitrixVirtual Apps And Desktops Version2203 Updatecu2 SwEditionltsr
CitrixVirtual Apps And Desktops Version2203 Updatecu3 SwEditionltsr
CitrixVirtual Apps And Desktops Version2203 Updatecu4 SwEditionltsr
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.295
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
secure@citrix.com 8.5 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.