VDI vulnerabilities

Showing 51 - 100 of 148 CVEs

  1. CVE-2024-8069 Published Nov 12, 2024

    Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

  2. CVE-2024-8068 Published Nov 12, 2024

    Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

  3. CVE-2024-43599 Published Oct 8, 2024

    Remote Desktop Client Remote Code Execution Vulnerability

  4. CVE-2024-43533 Published Oct 8, 2024

    Remote Desktop Client Remote Code Execution Vulnerability

  5. CVE-2024-38813 Published Sep 17, 2024

    The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

  6. CVE-2024-38812 Published Sep 17, 2024

    The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

  7. CVE-2024-7889 Published Sep 11, 2024

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  8. CVE-2024-5148 Published Sep 2, 2024

    A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

  9. CVE-2024-21302 Published Aug 8, 2024

    Summary: Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files with outdated versions. By exploiting this vulnerability, an attacker could reintroduce previously mitigated vulnerabilities, circumvent some features of VBS, and exfiltrate data protected by VBS. Microsoft is developing a security update to mitigate this threat, but it is not yet available. Guidance to help customers reduce the risks associated with this vulnerability and to protect their systems until the mitigation is available in a Windows security update is provided in the Recommended Actions section of this CVE. This CVE will be updated when the mitigation is available in a Windows security update. We highly encourage customers to subscribe to Security Update Guide notifications to receive an alert when this update occurs. Update: August 13, 2024 Microsoft has released the August 2024 security updates that include an opt-in revocation policy mitigation to address this vulnerability. Customers running affected versions of Windows are encouraged to review KB5042562: Guidance for blocking rollback of virtualization-based security related updates to assess if this opt-in policy meets the needs of their environment before implementing this mitigation. There are risks associated with this mitigation that should be understood prior to applying it to your systems. Detailed information about these risks is also available in KB5042562. Details: A security researcher informed Microsoft of an elevation of privilege vulnerability in Windows 10, Windows 11, Windows Server 2016, and higher based systems including Azure Virtual Machines (VM) that support VBS. For more information on Windows versions and VM SKUs supporting VBS, reference: Virtualization-based Security (VBS) | Microsoft Learn. The vulnerability enables an attacker with administrator privileges on the target system to replace current Windows system files with outdated versions. Successful exploitation provides an attacker with the ability to reintroduce previously mitigated vulnerabilities, circumvent VBS security features, and exfiltrate data protected by VBS. Microsoft is developing a security... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21302

  10. CVE-2024-6286 Published Jul 10, 2024

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  11. CVE-2024-6236 Published Jul 10, 2024

    Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX

  12. CVE-2024-6151 Published Jul 10, 2024

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS

  13. CVE-2024-6150 Published Jul 10, 2024

    A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning

  14. CVE-2024-6149 Published Jul 10, 2024

    Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

  15. CVE-2024-6148 Published Jul 10, 2024

    Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

  16. CVE-2024-6235 Published Jul 10, 2024

    Sensitive information disclosure in NetScaler Console

  17. CVE-2024-5491 Published Jul 10, 2024

    Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

  18. CVE-2024-38080 Published Jul 9, 2024

    Windows Hyper-V Elevation of Privilege Vulnerability

  19. CVE-2024-38077 Published Jul 9, 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  20. CVE-2024-38076 Published Jul 9, 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  21. CVE-2024-38074 Published Jul 9, 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  22. CVE-2024-37081 Published Jun 18, 2024

    The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.

  23. CVE-2024-37080 Published Jun 18, 2024

    vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

  24. CVE-2024-37079 Published Jun 18, 2024

    vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

  25. CVE-2024-27244 Published May 15, 2024

    Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

  26. CVE-2024-22267 Published May 14, 2024

    VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

  27. CVE-2024-22253 Published Mar 5, 2024

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

  28. CVE-2024-22252 Published Mar 5, 2024

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

  29. CVE-2024-1709 Published Feb 21, 2024

    ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

  30. CVE-2024-1708 Published Feb 21, 2024

    ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

  31. CVE-2024-24697 Published Feb 14, 2024

    Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

  32. CVE-2024-24691 Published Feb 14, 2024

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

  33. CVE-2023-5914 Published Jan 17, 2024

      Cross-site scripting (XSS)

  34. CVE-2023-49647 Published Jan 12, 2024

    Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

  35. CVE-2024-21307 Published Jan 9, 2024

    Remote Desktop Client Remote Code Execution Vulnerability

  36. CVE-2023-4966 Published Oct 10, 2023

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

  37. CVE-2023-39213 Published Aug 8, 2023

    Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

  38. CVE-2023-3466 Published Jul 19, 2023

    Reflected Cross-Site Scripting (XSS)

  39. CVE-2023-3519 Published Jul 19, 2023

    Unauthenticated remote code execution

  40. CVE-2023-24490 Published Jul 10, 2023

    Users with only access to launch VDA applications can launch an unauthorized desktop

  41. CVE-2023-24486 Published Jul 10, 2023

    A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.

  42. CVE-2023-29362 Published Jun 14, 2023

    Remote Desktop Client Remote Code Execution Vulnerability

  43. CVE-2023-29352 Published Jun 14, 2023

    Windows Remote Desktop Security Feature Bypass Vulnerability

  44. CVE-2023-24485 Published Feb 16, 2023

    Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

  45. CVE-2023-24484 Published Feb 16, 2023

    A malicious user can cause log files to be written to a directory that they do not have permission to write to.

  46. CVE-2023-24483 Published Feb 16, 2023

    A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

  47. CVE-2022-27518 Published Dec 13, 2022

    Unauthenticated remote arbitrary code execution

  48. CVE-2022-28764 Published Nov 14, 2022

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

  49. CVE-2022-27513 Published Nov 8, 2022

    Remote desktop takeover via phishing

  50. CVE-2022-39422 Published Oct 18, 2022

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).