VulnerabilityModified
CVE-2014-4700
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
MEDIUM 4.9EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
- CVSS 2.0
- 4.9 MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- citrix/xendesktop
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/59889Third Party Advisory
- http://support.citrix.com/article/CTX139591Patch, Vendor Advisory
- http://www.securityfocus.com/bid/68530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030566Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94460Third Party Advisory, VDB Entry
- http://secunia.com/advisories/59889Third Party Advisory
- http://support.citrix.com/article/CTX139591Patch, Vendor Advisory
- http://www.securityfocus.com/bid/68530Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030566Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94460Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.