Contact Support

Customers who viewed this article also viewed

banner icon

Identify Changes in NetScaler build files with

File Integrity Monitoring

Learn More Watch Video
CTX319750 {{tooltipText}}

Citrix Virtual Apps and Desktops Security Update

Applicable Products

  • Citrix Virtual Apps and Desktops

Description of Problem

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.


This vulnerability has the following identifier:

CVE IDDescriptionVulnerability TypePre-conditions
CVE-2021-22928Local privilege escalation on a Windows VDACWE-284: Improper Access ControlAuthenticated access to a VDA with Citrix Profile Management or Citrix Profile Management WMI Plugin installed

The vulnerability affects the following supported versions of Citrix Virtual Apps and Desktops and XenApp / XenDesktop:
  • Citrix Virtual Apps and Desktops 2106 and earlier Current Release (CR) versions
  • Citrix Virtual Apps and Desktops 1912 LTSR CU3 and earlier versions of 1912 LTSR
  • Citrix XenApp / XenDesktop 7.15 LTSR CU7 and earlier versions of 7.15 LTSR

Citrix Virtual Apps and Desktops 2106 is only affected when Citrix Profile Management is installed on a Windows VDA as Citrix Profile Management WMI Plugin is not affected in this version.

Please note that Citrix XenApp / XenDesktop 7.6 LTSR has now reached End of Life and is no longer supported except through Citrix Extended Support Program.


Mitigating Factors

Customers are not affected by this issue if they have disabled Windows Installer on Windows VDAs by configuring the Group Policy setting:

Computer Configuration\Administrative templates\Windows components\windows installer\Turn off Windows Installer 

to Enabled - Always.


What Customers Should Do

Citrix has released hotfixes to address the vulnerability in the following supported versions:

 

Citrix Virtual Apps and Desktops 2106

 

Citrix Virtual Apps and Desktops 1912 LTSR

 

Citrix XenApp / XenDesktop 7.15 LTSR

 

Customers who have installed both affected components should install all applicable hotfixes. Customers who have only installed one of the affected components should install the hotfix that applies to the component they have installed. 

Citrix recommends that customers install any applicable hotfixes on affected Windows VDAs as soon as possible. 

This issue will also be addressed in any future versions of Citrix Virtual Apps and Desktops and Citrix XenApp / XenDesktop.

Acknowledgements

Citrix would like to thank Lasse Trolle Borup of Improsec A/S for working with us to protect Citrix customers.

What Citrix is Doing

Citrix is notifying customers and channel partners about this potential security issue through the publication of this security bulletin on the Citrix Knowledge Center at https://support.citrix.com/securitybulletins.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.

Subscribe to Receive Alerts

Citrix strongly recommends that all customers subscribe to receive alerts when a Citrix security bulletin is created or modified at https://support.citrix.com/user/alerts.

Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please see the following webpage: https://www.citrix.com/about/trust-center/vulnerability-process.html.

Disclaimer

This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document is at your own risk. Citrix reserves the right to change or update this document at any time. Customers are therefore recommended to always view the latest version of this document directly from the Citrix Knowledge Center.

Changelog

Date 

Change

2021-07-13

Initial Publication

2021-07-13

Additional hotfixes added

2021-07-16 Updated Profile Management hotfixes for 1912 LTSR (3002)
2021-07-23 Added mitigation advice and clarification for 7.6 LTSR
2021-07-28 Updated Profile Management hotfixes for 1912 LTSR (3003)