CVE-2021-22928 is a local privilege escalation vulnerability affecting Citrix Virtual Apps and Desktops, XenApp, and XenDesktop. An authenticated user on a Windows Virtual Delivery Agent (VDA) with Citrix Profile Management or WMI Plugin installed can escalate their privileges to SYSTEM. This high-severity flaw (CVSS 7.8) has a low attack complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2006, <= 2106CPE matchmatch criteria | cpe:2.3:a:citrix:virtual_apps_and_desktops:*:*:*:*:-:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:-:*:*:ltsr:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:virtual_apps_and_desktops:1912:cu3:*:*:*:*:*:* | ||
7.15CPE matchmatch criteria | cpe:2.3:a:citrix:xenapp:7.15:-:*:*:ltsr:*:*:* | ||
7.15CPE matchmatch criteria | cpe:2.3:a:citrix:xenapp:7.15:cu6:*:*:ltsr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.