A vulnerability has been discovered in Citrix uberAgent, which, if exploited, may result in the escalation of privileges of the attacker.
This vulnerability only impacts uberAgent and does not impact any other Citrix and or Cloud Software Group products.
The following supported versions of Citrix uberAgent are affected by the vulnerability:
Citrix uberAgent before 7.1.2
For all Citrix uberAgent versions before 7.1.2
At least one configured [CitrixADC_Config]entry plus one of the following metrics configured:
[Timer]
CitrixADCPerformance
CitrixADCvServer
CitrixADCGateways
CitrixADCInventory
In addition for Citrix uberAgent versions 7.0, 7.0.1, 7.0.2, 7.1, 7.1.1
WmiProvider set to PowerShell and at least one CitrixSession metric configured:
[Miscellaneous]
WmiProvider = PowerShell
[Timer]
CitrixSessionVirtualChannelDetail
CitrixSessionConfig
CVE ID | Description | Pre-requisites | CWE |
CVE-2024-3902 | Privilege escalation | See section: Pre-conditions | CWE-269 |
For all Citrix uberAgent versions before 7.1.2
Disable all CitrixADC metrics by removing the following timer properties:
[Timer]
CitrixADCPerformance
CitrixADCvServer
CitrixADCGateways
CitrixADCInventory
Remove all [CitrixADC_Config] entries.
In addition for Citrix uberAgent versions 7.0, 7.0.1, 7.0.2, 7.1, 7.1.1
Ensure that WmiProvider is set to WMIC or not configured.
Cloud Software Group strongly urges affected customers of Citrix uberAgent to install the relevant updated versions of Citrix uberAgent as soon as possible:
Citrix uberAgent 7.1.2 and later
The latest Citrix uberAgent versions can be downloaded here: https://uberagent.com/download/uberagent/
2024-04-18 T 16:00:00Z | Initial publication |
2024-07-13 T 15:45:00Z | Platform migration |