Lucene search

K
citrixCitrixCTX282684
HistoryOct 13, 2020 - 4:00 a.m.

Citrix Gateway Plug-in for Windows Security Update

2020-10-1304:00:00
support.citrix.com
66

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

Description of Problem

Vulnerabilities have been identified in Citrix Gateway Plug-in for Windows that, if exploited, could result in a local user escalating their privilege level to SYSTEM.

The vulnerabilities have the following identifiers:

  • CVE-2020-8257
  • CVE-2020-8258

These vulnerabilities affect the following supported versions of Citrix Gateway Plug-in for Windows:

Customers with Citrix ADC or Citrix Gateway:

  • Citrix Gateway Plug-in 13.0 for Windows before 64.35
  • Citrix Gateway Plug-in 12.1 for Windows before 59.16

Customers with Citrix ADC 12.1-FIPS:

  • Citrix Gateway Plug-in 12.1 for Windows before 55.190

These vulnerabilities do not affect Citrix Gateway Plug-in on other platforms.

Citrix Gateway Plug-in for Windows 11.1 is not affected by these vulnerabilities. Other versions are now End-of-Life and no longer supported.

The following supported versions of Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway) include an impacted version of Citrix Gateway Plug-in in order to distribute it to users when they connect to Citrix Gateway:

  • Citrix ADC and Citrix Gateway 13.0 before 64.35
  • NetScaler ADC and NetScaler Gateway 12.1 before 59.16
  • Citrix ADC 12.1-FIPS before 55.190

What Customers Should Do

Citrix strongly recommends that:

customers with Citrix Gateway and customers using the SSL VPN component of Citrix ADC upgrade to a version that includes and distributes a fixed version of Citrix Gateway Plug-in for Windows.

AND

customers with users who have a vulnerable version of Citrix Gateway Plug-in for Windows ensure they upgrade to a fixed version of Citrix Gateway Plug-in for Windows as soon as possible. This can be achieved when they log in to a supported version of Citrix ADC or Citrix Gateway or by installing a compatible fixed version from Citrix.com.

The issues have been addressed in the following versions of Citrix Gateway Plug-in for Windows:

Customers with Citrix ADC or Citrix Gateway:

  • Citrix Gateway Plug-in 13.0 for Windows 64.35 and later versions
  • Citrix Gateway Plug-in 12.1 for Windows 59.16 and later versions

Customers with Citrix ADC 12.1-FIPS:

  • Citrix Gateway Plug-in 12.1 for Windows 55.190 and later versions

The latest versions of Citrix Gateway Plug-in for Windows are available from:

<https://www.citrix.com/downloads/citrix-gateway/plug-ins/&gt;

Please note that versions of Citrix Gateway Plug-in which are compatible with Citrix ADC 12.1-FIPS are delivered directly from Citrix ADC 12.1-FIPS and are not available from Citrix.com.

Fixed versions of Citrix Gateway Plug-in for Windows are included in the following versions of Citrix ADC and Citrix Gateway:

  • Citrix ADC and Citrix Gateway 13.0-64.35 and later releases
  • NetScaler ADC and NetScaler Gateway 12.1-59.16 and later releases
  • Citrix ADC 12.1-FIPS 55.190 and later releases

The latest versions of Citrix ADC and Citrix Gateway are available from:

<https://www.citrix.com/downloads/citrix-adc/&gt;

<https://www.citrix.com/downloads/citrix-gateway/&gt;


Acknowledgements

Citrix would like to thank Chen Erlich of Cymptom (@chen_erlich) for working with us to protect Citrix customers.


What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at _ <http://support.citrix.com/&gt;_.


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at _ <https://www.citrix.com/support/open-a-support-case.html&gt;_.


Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please see the following webpage: <https://www.citrix.com/about/trust-center/vulnerability-process.html&gt;


Changelog

Date Change
2020-10-13 Initial Publication

Affected configurations

Vulners
Node
citrixxenRange13.0
OR
citrixxenRange64.35
OR
citrixxenRange14.0.0
OR
citrixxenRange15.0.0
OR
citrixxenRange16.0.0
OR
citrixxenRange17.0.0
OR
citrixxenRange18.0.0
OR
citrixxenRange19.0.0
OR
citrixxenRange20.0.0
OR
citrixxenRange21.0.0
OR
citrixxenRange22.0.0
OR
citrixxenRange23.0.0
OR
citrixxenRange24.0.0
OR
citrixxenRange25.0.0
OR
citrixxenRange26.0.0
OR
citrixxenRange27.0.0
OR
citrixxenRange28.0.0
OR
citrixxenRange29.0.0
OR
citrixxenRange30.0.0
OR
citrixxenRange31.0.0
OR
citrixxenRange32.0.0
OR
citrixxenRange33.0.0
OR
citrixxenRange34.0.0
OR
citrixxenRange35.0.0
OR
citrixxenRange36.0.0
OR
citrixxenRange37.0.0
OR
citrixxenRange38.0.0
OR
citrixxenRange39.0.0
OR
citrixxenRange40.0.0
OR
citrixxenRange41.0.0
OR
citrixxenRange42.0.0
OR
citrixxenRange43.0.0
OR
citrixxenRange44.0.0
OR
citrixxenRange45.0.0
OR
citrixxenRange46.0.0
OR
citrixxenRange47.0.0
OR
citrixxenRange48.0.0
OR
citrixxenRange49.0.0
OR
citrixxenRange50.0.0
OR
citrixxenRange51.0.0
OR
citrixxenRange52.0.0
OR
citrixxenRange53.0.0
OR
citrixxenRange54.0.0
OR
citrixxenRange55.0.0
OR
citrixxenRange56.0.0
OR
citrixxenRange57.0.0
OR
citrixxenRange58.0.0
OR
citrixxenRange59.0.0
OR
citrixxenRange60.0.0
OR
citrixxenRange61.0.0
OR
citrixxenRange62.0.0
OR
citrixxenRange63.0.0
OR
citrixgatewayRange13.0
OR
citrixgatewayRange64.35
OR
citrixgatewayRange14.0.0
OR
citrixgatewayRange15.0.0
OR
citrixgatewayRange16.0.0
OR
citrixgatewayRange17.0.0
OR
citrixgatewayRange18.0.0
OR
citrixgatewayRange19.0.0
OR
citrixgatewayRange20.0.0
OR
citrixgatewayRange21.0.0
OR
citrixgatewayRange22.0.0
OR
citrixgatewayRange23.0.0
OR
citrixgatewayRange24.0.0
OR
citrixgatewayRange25.0.0
OR
citrixgatewayRange26.0.0
OR
citrixgatewayRange27.0.0
OR
citrixgatewayRange28.0.0
OR
citrixgatewayRange29.0.0
OR
citrixgatewayRange30.0.0
OR
citrixgatewayRange31.0.0
OR
citrixgatewayRange32.0.0
OR
citrixgatewayRange33.0.0
OR
citrixgatewayRange34.0.0
OR
citrixgatewayRange35.0.0
OR
citrixgatewayRange36.0.0
OR
citrixgatewayRange37.0.0
OR
citrixgatewayRange38.0.0
OR
citrixgatewayRange39.0.0
OR
citrixgatewayRange40.0.0
OR
citrixgatewayRange41.0.0
OR
citrixgatewayRange42.0.0
OR
citrixgatewayRange43.0.0
OR
citrixgatewayRange44.0.0
OR
citrixgatewayRange45.0.0
OR
citrixgatewayRange46.0.0
OR
citrixgatewayRange47.0.0
OR
citrixgatewayRange48.0.0
OR
citrixgatewayRange49.0.0
OR
citrixgatewayRange50.0.0
OR
citrixgatewayRange51.0.0
OR
citrixgatewayRange52.0.0
OR
citrixgatewayRange53.0.0
OR
citrixgatewayRange54.0.0
OR
citrixgatewayRange55.0.0
OR
citrixgatewayRange56.0.0
OR
citrixgatewayRange57.0.0
OR
citrixgatewayRange58.0.0
OR
citrixgatewayRange59.0.0
OR
citrixgatewayRange60.0.0
OR
citrixgatewayRange61.0.0
OR
citrixgatewayRange62.0.0
OR
citrixgatewayRange63.0.0
OR
citrixnetscalerRange12.1
OR
citrixnetscalerRange59.16
OR
citrixnetscalerRange13.0.0
OR
citrixnetscalerRange14.0.0
OR
citrixnetscalerRange15.0.0
OR
citrixnetscalerRange16.0.0
OR
citrixnetscalerRange17.0.0
OR
citrixnetscalerRange18.0.0
OR
citrixnetscalerRange19.0.0
OR
citrixnetscalerRange20.0.0
OR
citrixnetscalerRange21.0.0
OR
citrixnetscalerRange22.0.0
OR
citrixnetscalerRange23.0.0
OR
citrixnetscalerRange24.0.0
OR
citrixnetscalerRange25.0.0
OR
citrixnetscalerRange26.0.0
OR
citrixnetscalerRange27.0.0
OR
citrixnetscalerRange28.0.0
OR
citrixnetscalerRange29.0.0
OR
citrixnetscalerRange30.0.0
OR
citrixnetscalerRange31.0.0
OR
citrixnetscalerRange32.0.0
OR
citrixnetscalerRange33.0.0
OR
citrixnetscalerRange34.0.0
OR
citrixnetscalerRange35.0.0
OR
citrixnetscalerRange36.0.0
OR
citrixnetscalerRange37.0.0
OR
citrixnetscalerRange38.0.0
OR
citrixnetscalerRange39.0.0
OR
citrixnetscalerRange40.0.0
OR
citrixnetscalerRange41.0.0
OR
citrixnetscalerRange42.0.0
OR
citrixnetscalerRange43.0.0
OR
citrixnetscalerRange44.0.0
OR
citrixnetscalerRange45.0.0
OR
citrixnetscalerRange46.0.0
OR
citrixnetscalerRange47.0.0
OR
citrixnetscalerRange48.0.0
OR
citrixnetscalerRange49.0.0
OR
citrixnetscalerRange50.0.0
OR
citrixnetscalerRange51.0.0
OR
citrixnetscalerRange52.0.0
OR
citrixnetscalerRange53.0.0
OR
citrixnetscalerRange54.0.0
OR
citrixnetscalerRange55.0.0
OR
citrixnetscalerRange56.0.0
OR
citrixnetscalerRange57.0.0
OR
citrixnetscalerRange58.0.0
OR
citrixnetscaler_gatewayRange12.1
OR
citrixnetscaler_gatewayRange59.16
OR
citrixnetscaler_gatewayRange13.0.0
OR
citrixnetscaler_gatewayRange14.0.0
OR
citrixnetscaler_gatewayRange15.0.0
OR
citrixnetscaler_gatewayRange16.0.0
OR
citrixnetscaler_gatewayRange17.0.0
OR
citrixnetscaler_gatewayRange18.0.0
OR
citrixnetscaler_gatewayRange19.0.0
OR
citrixnetscaler_gatewayRange20.0.0
OR
citrixnetscaler_gatewayRange21.0.0
OR
citrixnetscaler_gatewayRange22.0.0
OR
citrixnetscaler_gatewayRange23.0.0
OR
citrixnetscaler_gatewayRange24.0.0
OR
citrixnetscaler_gatewayRange25.0.0
OR
citrixnetscaler_gatewayRange26.0.0
OR
citrixnetscaler_gatewayRange27.0.0
OR
citrixnetscaler_gatewayRange28.0.0
OR
citrixnetscaler_gatewayRange29.0.0
OR
citrixnetscaler_gatewayRange30.0.0
OR
citrixnetscaler_gatewayRange31.0.0
OR
citrixnetscaler_gatewayRange32.0.0
OR
citrixnetscaler_gatewayRange33.0.0
OR
citrixnetscaler_gatewayRange34.0.0
OR
citrixnetscaler_gatewayRange35.0.0
OR
citrixnetscaler_gatewayRange36.0.0
OR
citrixnetscaler_gatewayRange37.0.0
OR
citrixnetscaler_gatewayRange38.0.0
OR
citrixnetscaler_gatewayRange39.0.0
OR
citrixnetscaler_gatewayRange40.0.0
OR
citrixnetscaler_gatewayRange41.0.0
OR
citrixnetscaler_gatewayRange42.0.0
OR
citrixnetscaler_gatewayRange43.0.0
OR
citrixnetscaler_gatewayRange44.0.0
OR
citrixnetscaler_gatewayRange45.0.0
OR
citrixnetscaler_gatewayRange46.0.0
OR
citrixnetscaler_gatewayRange47.0.0
OR
citrixnetscaler_gatewayRange48.0.0
OR
citrixnetscaler_gatewayRange49.0.0
OR
citrixnetscaler_gatewayRange50.0.0
OR
citrixnetscaler_gatewayRange51.0.0
OR
citrixnetscaler_gatewayRange52.0.0
OR
citrixnetscaler_gatewayRange53.0.0
OR
citrixnetscaler_gatewayRange54.0.0
OR
citrixnetscaler_gatewayRange55.0.0
OR
citrixnetscaler_gatewayRange56.0.0
OR
citrixnetscaler_gatewayRange57.0.0
OR
citrixnetscaler_gatewayRange58.0.0
OR
citrixxenRange12.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

60.7%

Related for CTX282684