Symptoms or Error
Description
A high severity issue has been discovered in Citrix StoreFront that, if exploited, would allow an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
This issue has the following identifier:
- CVE-2020-8200
The issue affects the following supported Current Release (CR) versions of Citrix StoreFront:
- Citrix StoreFront before 2006
The issue affects the following supported Long Term Service Release (LTSR) versions of Citrix StoreFront:
- Citrix StoreFront 1912 LTSR before CU1 (1912.0.1000)
- Citrix StoreFront 3.12 for 7.15 LTSR before CU5 Hotfix (3.12.5001)
- Citrix StoreFront 3.0 for 7.6 LTSR before CU8 Hotfix (3.0.8001)
Note that Citrix StoreFront is included as part of Citrix Virtual Apps and Desktops. Therefore, some customers may be affected who have not independently installed Citrix StoreFront.
Customers running Citrix Virtual Apps and Desktops 2003 should note that the version of Citrix StoreFront included in that release, 1912 LTSR, is one of the affected versions.