Citrix Faces New RCE Threats with Zero-Day Vulnerabilities

1 min read
Source: The Hacker News
Citrix Faces New RCE Threats with Zero-Day Vulnerabilities
Photo: The Hacker News
TL;DR Summary

New security flaws in Citrix Virtual Apps and Desktop could allow unauthenticated remote code execution (RCE) due to misconfigured MSMQ permissions and the use of BinaryFormatter for deserialization. The vulnerabilities, CVE-2024-8068 and CVE-2024-8069, require attackers to be authenticated users within the same Windows Active Directory domain. Citrix has released patches for affected versions, and Microsoft advises against using BinaryFormatter due to its security risks.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

2 min

vs 3 min read

Condensed

87%

51164 words

Want the full story? Read the original article

Read on The Hacker News