Skip to main content

Citrix Releases Security Update for Log4j2 Vulnerabilities

Citrix has released a security advisory about Log4j2 vulnerabilities in Citrix Endpoint Management and Citrix Virtual Apps and Desktops.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Citrix has released a security advisory about Log4j2 vulnerabilities in Citrix Endpoint Management and Citrix Virtual Apps and Desktops.


Threat details

Introduction

Citrix has released and updated their advisory to address the Log4Shell vulnerabilities in Citrix Endpoint Management (Citrix XenMobile Server) and Citrix Virtual Apps and Desktops (XenApp & XenDesktop). An unauthenticated remote attacker could exploit these vulnerabilities to execute arbitrary code, cause a denial-of-service, and take control of affected systems.

NHS Digital response to Log4Shell

This alert is part of NHS Digital's wider response to the Log4Shell remote code execution vulnerability. For more information on Log4Shell itself, please visit our cyber alerts article Log4Shell RCE Vulnerability CC-3989.
 

Additional Citrix systems may be vulnerable and affected organisations should regularly review the Citrix Security Advisory for CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832. NHS and social care organisations are invited to use the Cyber Associates Network to find out additional information and participate in discussion about the Log4Shell remote code execution vulnerability and affected Citrix products.


Remediation advice

Affected organisations are encouraged to review the Citrix Security Advisory CTX335705 and review the Citrix support articles below and apply any necessary updates or workarounds.


Remediation steps

Type Step
Patch

XenMobile Server 10.14 RP2 | CTX335763


https://support.citrix.com/article/CTX335763
Patch

XenMobile Server 10.14 RP3 | CTX335897


https://support.citrix.com/article/CTX335897
Patch

XenMobile Server 10.13 RP5 |CTX335753


https://support.citrix.com/article/CTX335753
Patch

XenMobile Server 10.13 RP6 |CTX335875


https://support.citrix.com/article/CTX335875
Patch

XenMobile Server 10.12 RP10 | CTX335785


https://support.citrix.com/article/CTX335785
Patch

XenMobile Server 10.12 RP11 | CTX335861


https://support.citrix.com/article/CTX335861
Patch

Citrix Virtual Apps and Desktops (XenApp & XenDesktop)


https://support.citrix.com/article/CTX335705


CVE Vulnerabilities

Last edited: 5 January 2022 3:20 pm