CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

citrix

virtual_apps_and_desktops

9 known vulnerabilities · sorted by CVSS score

CVE-2020-8283
HIGH8.8

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

citrix / virtual_apps_and_desktops+13
Network
Published Dec 14, 2020
CVE-2020-8269
HIGH8.8

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

citrix / virtual_apps_and_desktops+13
Network
Published Nov 16, 2020
CVE-2020-8270
HIGH8.8

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

citrix / virtual_apps_and_desktops+1
Network
Published Nov 16, 2020
CVE-2025-6759
HIGH7.8

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

citrix / virtual_apps_and_desktops+3
Local
Published Jul 8, 2025
CVE-2024-6151
HIGH7.8

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS

citrix / virtual_apps_and_desktops+14
Local
Published Jul 10, 2024
CVE-2023-24483
HIGH7.8

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

citrix / virtual_apps_and_desktops+8
Local
Published Feb 16, 2023
CVE-2021-22928
HIGH7.8

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

citrix / virtual_apps_and_desktops+8
Local
Published Aug 5, 2021
CVE-2023-24490
MEDIUM6.3

Users with only access to launch VDA applications can launch an unauthorized desktop

citrix / virtual_apps_and_desktops+21
Network
Published Jul 10, 2023
CVE-2023-6184
MEDIUM5.0

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

citrix / virtual_apps_and_desktops+13
Network
Published Jan 18, 2024