Windows and Linux Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2023-24490

Related Vulnerabilities: CVE-2023-24490  

A vulnerability has been identified that impacts Virtual Delivery Agents for Windows or Linux used by Citrix Virtual Apps and Desktops and Citrix DaaS. 

Description of Problem

A vulnerability has been identified that impacts Virtual Delivery Agents for Windows or Linux used by Citrix Virtual Apps and Desktops and Citrix DaaS. 

The vulnerability affects the following supported versions of Windows Virtual Delivery Agent

Current Release (CR)

  • Citrix Virtual Apps and Desktops versions before 2305 

Long Term Service Release (LTSR)

  • Citrix Virtual Apps and Desktops 2203 LTSR before CU3
  • Citrix Virtual Apps and Desktops 1912 LTSR before CU7

The vulnerability affects the following supported versions of Linux Virtual Delivery Agent

Current Release (CR)

  • Linux Virtual Delivery Agent versions before 2305

Long Term Service Release (LTSR)

  • Linux Virtual Delivery Agent 2203 LTSR before CU3
  • Linux Virtual Delivery Agent 1912 LTSR before CU7 hotfix 1(19.12.7001)

The vulnerability has been given the following identifier: 

CVE ID Description Pre-requisites CWE CVSS
CVE-2023-24490 Users with only access to launch VDA applications can launch an unauthorized desktop Authorized user with the ability to launch a virtual application CWE-284 6.3

What Customers Should Do

Citrix strongly recommends that customers upgrade their Windows and Linux Virtual Delivery Agents to versions that contain the fixes as soon as possible.  

Windows Virtual Delivery Agent versions that contain the fixes are: 

  • Citrix Virtual Apps and Desktops 2305 and later versions 
  • Citrix Virtual Apps and Desktops 2203 LTSR CU3 and later cumulative updates
  • Citrix Virtual Apps and Desktops 1912 LTSR CU7 and later cumulative updates

Linux Virtual Delivery Agent versions that contain the fixes are: 

  • Linux Virtual Delivery Agent 2305 and later versions
  • Linux Virtual Delivery Agent 2203 LTSR CU3 and later cumulative updates
  • Linux Virtual Delivery Agent 1912 LTSR CU7 hotfix 1(19.12.7001) and later cumulative updates

Note: Customers are recommended only to upgrade their Windows and Linux Virtual Delivery Agents to address this vulnerability. 

The latest versions of Citrix Virtual Apps and Desktops are available from the following Citrix website location: 

https://www.citrix.com/downloads/citrix-virtual-apps-and-desktops/

Extended support customers are recommended to contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/en-gb/support/open-a-support-case/  


Additional Information:

Citrix Virtual Apps and Desktops and Citrix DaaS customers may use Citrix provisioning services, Machine creation services technologies, if applicable to update their non persistent Virtual Delivery Agents.

Citrix DaaS customers may use VDA Upgrade Service (VUS) to update their Windows persistent Virtual Delivery Agents for Remote PC Access, HDX Plus for Windows 365, and any other persistent or provisioned and dedicated catalogs. Customers are recommended to review the VUS Prerequisites to determine if they can use the VDA Upgrade Service.

 


Acknowledgements

Citrix would like to thank the Lockheed Martin Red Team for working with us to protect Citrix customers.

What Citrix is Doing

Citrix is notifying customers and channel partners about this potential security issue through the publication of this security bulletin on the Citrix Knowledge Center at https://support.citrix.com/securitybulletins.

Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.

Subscribe to Receive Alerts

Citrix strongly recommends that all customers subscribe to receive alerts when a Citrix security bulletin is created or modified at https://support.citrix.com/user/alerts.

Reporting Security Vulnerabilities to Citrix

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please see the following webpage: https://www.citrix.com/about/trust-center/vulnerability-process.html.

Disclaimer

This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document is at your own risk. Citrix reserves the right to change or update this document at any time. Customers are therefore recommended to always view the latest version of this document directly from the Citrix Knowledge Center.

Changelog

2023-06-13 T 13:30:00Z Initial publication
2023-06-14 T 20:00:00Z Added clarification in the 'What customers should do' section