Citrix Faces New RCE Threats with Zero-Day Vulnerabilities

TL;DR
New security flaws in Citrix Virtual Apps and Desktop could allow unauthenticated remote code execution (RCE) due to misconfigured MSMQ permissions and the use of BinaryFormatter for deserialization. The vulnerabilities, CVE-2024-8068 and CVE-2024-8069, require attackers to be authenticated users within the same Windows Active Directory domain. Citrix has released patches for affected versions, and Microsoft advises against using BinaryFormatter due to its security risks.
- New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration The Hacker News
- Visionaries Have Democratised Remote Network Access - Citrix Virtual Apps and Desktops (CVE Unknown) watchTowr Labs
- Exploit code released for RCE attack on Citrix VDI solution The Register
- Citrix Zero-Day Bug Allows Unauthenticated RCE Dark Reading
- New Citrix Zero-Day Vulnerability Allows Remote Code Execution Infosecurity Magazine
Want the full story? Read the original reporting
Read on The Hacker News