A high severity issue has been discovered in Citrix StoreFront that, if exploited, would allow an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
This issue has the following identifier:
The issue affects the following supported Current Release (CR) versions of Citrix StoreFront:
The issue affects the following supported Long Term Service Release (LTSR) versions of Citrix StoreFront:
Note that Citrix StoreFront is included as part of Citrix Virtual Apps and Desktops. Therefore, some customers may be affected who have not independently installed Citrix StoreFront.
Customers running Citrix Virtual Apps and Desktops 2003 should note that the version of Citrix StoreFront included in that release, 1912 LTSR, is one of the affected versions.
If users are not in the same Microsoft Active Directory domain as the Citrix StoreFront server, the vulnerability is not exploitable, even if the users are authenticated in a transitively trusted domain. Note that this applies even if the user is logged into the Citrix StoreFront server.
The issue has been addressed in the following Citrix StoreFront versions:
Citrix strongly recommends that customers running affected versions of Citrix StoreFront, both CR and LTSR versions,upgrade to a fixed version as soon as possible.
The latest versions of Citrix StoreFront can be downloaded from the following location:
https://www.citrix.com/downloads/storefront/
Citrix would like to thank Harrison Neal of Patch Advisor for working with us to protect Citrix customers.
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously.
For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please visit the Citrix Trust Center at https://www.citrix.com/about/trust-center/vulnerability-process.html
| Date | Change |
| 2020-09-08 | Initial Publication |
| 2020-09-10 | Change in page formatting |
| 2020-09-10 | Update to the affected versions |
Security vulnerability
A high severity issue has been discovered in Citrix StoreFront that, if exploited, would allow an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server. This issue has the following identifier: CVE-2020-8200