Citrix StoreFront Security Update - Security Bulletin

Related Vulnerabilities: CVE-2020-8200  

Symptoms or Error

Description


A high severity issue has been discovered in Citrix StoreFront that, if exploited, would allow an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.


This issue has the following identifier:
 
  • CVE-2020-8200

The issue affects the following supported Current Release (CR) versions of Citrix StoreFront:
 
  • Citrix StoreFront before 2006

The issue affects the following supported Long Term Service Release (LTSR) versions of Citrix StoreFront:
 
  • Citrix StoreFront 1912 LTSR before CU1 (1912.0.1000)
 
  • Citrix StoreFront 3.12 for 7.15 LTSR before CU5 Hotfix (3.12.5001)
 
  • Citrix StoreFront 3.0 for 7.6 LTSR before CU8 Hotfix (3.0.8001)

Note that Citrix StoreFront is included as part of Citrix Virtual Apps and Desktops. Therefore, some customers may be affected who have not independently installed Citrix StoreFront.

Customers running Citrix Virtual Apps and Desktops 2003 should note that the version of Citrix StoreFront included in that release, 1912 LTSR, is one of the affected versions.

Solution

Mitigating Factors

If users are not in the same Microsoft Active Directory domain as the Citrix StoreFront server, the vulnerability is not exploitable, even if the users are authenticated in a transitively trusted domain. Note that this applies even if the user is logged into the Citrix StoreFront server.


What Customers Should Do


The issue has been addressed in the following Citrix StoreFront versions:
 
  • Citrix StoreFront 1912 CU1 (1912.0.1000) and later versions of Citrix StoreFront 1912 LTSR
 
  • Citrix StoreFront 3.0 for 7.6 LTSR CU8 Hotfix (3.0.8001) and later versions of StoreFront 3.0 for 7.6 LTSR
 
  • Citrix StoreFront 3.12 for 7.15 LTSR CU5 Hotfix (3.12.5001) and later versions of StoreFront 3.12 for 7.15 LTSR

Citrix strongly recommends that customers running affected versions of Citrix StoreFront, both CR and LTSR versions,upgrade to a fixed version as soon as possible.

The latest versions of Citrix StoreFront can be downloaded from the following location:

https://www.citrix.com/downloads/storefront/ 

https://support.citrix.com/article/CTX277537 

https://support.citrix.com/article/CTX277538


Acknowledgements

Citrix would like to thank Harrison Neal of Patch Advisor for working with us to protect Citrix customers.


What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/ 


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html


Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously.

For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please visit the Citrix Trust Center at https://www.citrix.com/about/trust-center/vulnerability-process.html

 

Changelog

Date Change
2020-09-08 Initial Publication
2020-09-10 Change in page formatting
2020-09-10 Update to the affected versions

Problem Cause

Security vulnerability