Lucene search

K
nvd[email protected]NVD:CVE-2023-24483
HistoryFeb 16, 2023 - 6:15 p.m.

CVE-2023-24483

2023-02-1618:15:11
CWE-269
web.nvd.nist.gov
5
vulnerability
local user
privilege elevation
citrix
windows vda

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.

Affected configurations

Nvd
Node
microsoftwindowsMatch-
AND
citrixvirtual_apps_and_desktopsRange<2212-
OR
citrixvirtual_apps_and_desktopsMatch1912-ltsr
OR
citrixvirtual_apps_and_desktopsMatch1912cu1ltsr
OR
citrixvirtual_apps_and_desktopsMatch1912cu2ltsr
OR
citrixvirtual_apps_and_desktopsMatch1912cu3ltsr
OR
citrixvirtual_apps_and_desktopsMatch1912cu4ltsr
OR
citrixvirtual_apps_and_desktopsMatch1912cu5ltsr
OR
citrixvirtual_apps_and_desktopsMatch2203-ltsr
OR
citrixvirtual_apps_and_desktopsMatch2203cu1ltsr
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
citrixvirtual_apps_and_desktops*cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:-:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:-:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu1:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu2:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu3:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu4:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops1912cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu5:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops2203cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:-:*:*:ltsr:*:*:*
citrixvirtual_apps_and_desktops2203cpe:2.3:a:citrix:virtual_apps_and_desktops:2203:cu1:*:*:ltsr:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%