logo

HTTP your way into Citrix's Virtual Apps and Desktops with fresh exploit code

ID: e3dd0130-6e8d-52c8-8a7f-b754b4622f5f

STIX ID: report--e3dd0130-6e8d-52c8-8a7f-b754b4622f5f

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-11-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers published a PoC showing that insecure MSMQ-over-HTTP configuration and use of .NET BinaryFormatter in Citrix Virtual Apps and Desktops' Session Recording Manager can allow deserialization-based privilege escalation and limited RCE against the VDI host; Citrix disputes the unauthenticated RCE claim, issued hotfixes for multiple releases, and assigned two CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.