| CVE ID | Published | Description | Score | Severity |
|---|---|---|---|---|
| Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS | 7.3 |
High |
||
| Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | 7.2 |
High |
||
| Users with only access to launch VDA applications can launch an unauthorized desktop | 6.3 |
Medium |
||
| A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | 7.8 |
High |
||
| A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM. | 7.8 |
High |