HTTP your way into Citrix's Virtual Apps and Desktops with fresh exploit code
ID: e3dd0130-6e8d-52c8-8a7f-b754b4622f5f
STIX ID: report--e3dd0130-6e8d-52c8-8a7f-b754b4622f5f
Feed Name: The Register (Security)
Threat Score
Researchers published a PoC showing that insecure MSMQ-over-HTTP configuration and use of .NET BinaryFormatter in Citrix Virtual Apps and Desktops' Session Recording Manager can allow deserialization-based privilege escalation and limited RCE against the VDI host; Citrix disputes the unauthenticated RCE claim, issued hotfixes for multiple releases, and assigned two CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
