Headline
CVE-2023-24490: Windows and Linux Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2023-24490
Users with only access to launch VDA applications can launch an unauthorized desktop
CTX559370
{{tooltipText}}
Security Bulletin | Severity: Medium | {{likeCount}} found this helpful | Created: {{articleFormattedCreatedDate}} | Modified: {{articleFormattedModifiedDate}} | Status: Final
Description of Problem
A vulnerability has been identified that impacts Virtual Delivery Agents for Windows or Linux used by Citrix Virtual Apps and Desktops and Citrix DaaS.
The vulnerability affects the following supported versions of Windows Virtual Delivery Agent:
Current Release (CR)
- Citrix Virtual Apps and Desktops versions before 2305
Long Term Service Release (LTSR)
- Citrix Virtual Apps and Desktops 2203 LTSR before CU3
- Citrix Virtual Apps and Desktops 1912 LTSR before CU7
The vulnerability affects the following supported versions of Linux Virtual Delivery Agent:
Current Release (CR)
- Linux Virtual Delivery Agent versions before 2305
Long Term Service Release (LTSR)
- Linux Virtual Delivery Agent 2203 LTSR before CU3
- Linux Virtual Delivery Agent 1912 LTSR before CU7 hotfix 1(19.12.7001)
The vulnerability has been given the following identifier:
CVE ID
Description
Pre-requisites
CWE
CVSS
CVE-2023-24490
Users with only access to launch VDA applications can launch an unauthorized desktop
Authorized user with the ability to launch a virtual application
Improper Access ControlCWE-284
6.3
What Customers Should Do
Citrix strongly recommends that customers upgrade their Windows and Linux Virtual Delivery Agents to versions that contain the fixes as soon as possible.
Windows Virtual Delivery Agent versions that contain the fixes are:
- Citrix Virtual Apps and Desktops 2305 and later versions
- Citrix Virtual Apps and Desktops 2203 LTSR CU3 and later cumulative updates
- Citrix Virtual Apps and Desktops 1912 LTSR CU7 and later cumulative updates
Linux Virtual Delivery Agent versions that contain the fixes are:
- Linux Virtual Delivery Agent 2305 and later versions
- Linux Virtual Delivery Agent 2203 LTSR CU3 and later cumulative updates
- Linux Virtual Delivery Agent 1912 LTSR CU7 hotfix 1(19.12.7001) and later cumulative updates
Note: Customers are recommended only to upgrade their Windows and Linux Virtual Delivery Agents to address this vulnerability.
The latest versions of Citrix Virtual Apps and Desktops are available from the following Citrix website location:
https://www.citrix.com/downloads/citrix-virtual-apps-and-desktops/
Extended support customers are recommended to contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/en-gb/support/open-a-support-case/
Additional Information:
Citrix Virtual Apps and Desktops and Citrix DaaS customers may use Citrix provisioning services, Machine creation services technologies, if applicable to update their non persistent Virtual Delivery Agents.
Citrix DaaS customers may use VDA Upgrade Service (VUS) to update their Windows persistent Virtual Delivery Agents for Remote PC Access, HDX Plus for Windows 365, and any other persistent or provisioned and dedicated catalogs. Customers are recommended to review the VUS Prerequisites to determine if they can use the VDA Upgrade Service.
Acknowledgements
Citrix would like to thank the Lockheed Martin Red Team for working with us to protect Citrix customers.
What Citrix is Doing
Citrix is notifying customers and channel partners about this potential security issue through the publication of this security bulletin on the Citrix Knowledge Center at https://support.citrix.com/securitybulletins.
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.
Subscribe to Receive Alerts
Citrix strongly recommends that all customers subscribe to receive alerts when a Citrix security bulletin is created or modified at https://support.citrix.com/user/alerts.
Reporting Security Vulnerabilities to Citrix
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please see the following webpage: https://www.citrix.com/about/trust-center/vulnerability-process.html.
Disclaimer
This document is provided on an “as is” basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document is at your own risk. Citrix reserves the right to change or update this document at any time. Customers are therefore recommended to always view the latest version of this document directly from the Citrix Knowledge Center.
Changelog
2023-06-13 T 13:30:00Z
Initial publication
2023-06-14 T 20:00:00Z
Added clarification in the ‘What customers should do’ section