CVE-2020-8270 is a critical arbitrary command execution vulnerability affecting Citrix Virtual Apps and Desktops (CVAD) versions before 2009, 1912 LTSR CU1, and 7.15 LTSR CU6. An unprivileged Windows or SMB user can leverage this flaw to execute commands as SYSTEM, leading to complete compromise of the affected system. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations should prioritize patching to mitigate this severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2006CPE matchmatch criteria | cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:-:*:*:* | ||
>= 1903, <= 1912CPE matchmatch criteria | cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:ltsr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.