Xendesktop

Vendor:

First CVE: Dec 26, 2012 · Active for 13 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Xendesktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2012
13 years ago
Most Recent CVE
Aug 5, 2021
1,815 days ago

CVE Severity & Scoring

Xendesktop8 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None5 (62.5%)
Unknown3 (37.5%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None2 (25.0%)
Unknown3 (37.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to mem
Aug 19, 20169.830NONO
An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU
Nov 16, 20208.827NONO
A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix
Aug 5, 20217.825NONO
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenD
Jun 1, 20167.524NONO
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CT
Dec 14, 20208.822NONO
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user'
Jul 11, 20144.919NONO
Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VD
Dec 26, 20125.018NONO
Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.
Nov 5, 20135.816NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Xendesktop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.638.11.6%00
7.517.50.9%00
7.1538.41.6%00
7.117.50.9%00
7.026.71.3%00
5.625.01.2%00
4.014.90.6%00