A vulnerability has been identified that impacts Virtual Delivery Agents for Windows or Linux used by Citrix Virtual Apps and Desktops and Citrix DaaS.
The vulnerability affects the following supported versions of Windows Virtual Delivery Agent:
Current Release (CR)
Long Term Service Release (LTSR)
The vulnerability affects the following supported versions of Linux Virtual Delivery Agent:
Current Release (CR)
Long Term Service Release (LTSR)
The vulnerability has been given the following identifier:
CVE ID | Description | Pre-requisites | CWE |
CVE-2023-24490 | Users with only access to launch VDA applications can launch an unauthorized desktop | Authorized user with the ability to launch a virtual application | CWE-284 |
Citrix strongly recommends that customers upgrade their Windows and Linux Virtual Delivery Agents to versions that contain the fixes as soon as possible.
Windows Virtual Delivery Agent versions that contain the fixes are:
Linux Virtual Delivery Agent versions that contain the fixes are:
Note: Customers are recommended only to upgrade their Windows and Linux Virtual Delivery Agents to address this vulnerability.
The latest versions of Citrix Virtual Apps and Desktops are available from the following Citrix website location:
https://www.citrix.com/downloads/citrix-virtual-apps-and-desktops/
Extended support customers are recommended to contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/en-gb/support/open-a-support-case/
Additional Information:
Citrix Virtual Apps and Desktops and Citrix DaaS customers may use Citrix provisioning services, Machine creation services technologies, if applicable to update their non persistent Virtual Delivery Agents.
Citrix DaaS customers may use VDA Upgrade Service (VUS) to update their Windows persistent Virtual Delivery Agents for Remote PC Access, HDX Plus for Windows 365, and any other persistent or provisioned and dedicated catalogs. Customers are recommended to review the VUS Prerequisites to determine if they can use the VDA Upgrade Service.
2023-06-13 T 13:30:00Z | Initial publication |
2023-06-14 T 20:00:00Z | Added clarification in the 'What customers should do' section |
2024-07-13 T 15:45:00Z | Platform migration |