Xendesktop
Vendor:
First CVE: Dec 26, 2012 · Active for 13 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xendesktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2012
13 years ago
Most Recent CVE
Aug 5, 2021
1,815 days ago
CVE Severity & Scoring
Xendesktop8 CVEs
38%
50%
13%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network4 (50.0%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None5 (62.5%)
Unknown3 (37.5%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None2 (25.0%)
Unknown3 (37.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6493CRITICAL Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to mem | Aug 19, 2016 | 9.8 | 30 | NO | NO |
CVE-2020-8269HIGH An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU | Nov 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2021-22928HIGH A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix | Aug 5, 2021 | 7.8 | 25 | NO | NO |
CVE-2016-4810HIGH Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenD | Jun 1, 2016 | 7.5 | 24 | NO | NO |
CVE-2020-8283HIGH An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CT | Dec 14, 2020 | 8.8 | 22 | NO | NO |
CVE-2014-4700MEDIUM Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user' | Jul 11, 2014 | 4.9 | 19 | NO | NO |
CVE-2012-6314MEDIUM Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VD | Dec 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2013-6077MEDIUM Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions. | Nov 5, 2013 | 5.8 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Xendesktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6 | 3 | 8.1 | 1.6% | 0 | 0 |
| 7.5 | 1 | 7.5 | 0.9% | 0 | 0 |
| 7.15 | 3 | 8.4 | 1.6% | 0 | 0 |
| 7.1 | 1 | 7.5 | 0.9% | 0 | 0 |
| 7.0 | 2 | 6.7 | 1.3% | 0 | 0 |
| 5.6 | 2 | 5.0 | 1.2% | 0 | 0 |
| 4.0 | 1 | 4.9 | 0.6% | 0 | 0 |