Citrix Releases Security Update for Log4j2 Vulnerabilities
Citrix has released a security advisory about Log4j2 vulnerabilities in Citrix Endpoint Management and Citrix Virtual Apps and Desktops.
Summary
Citrix has released a security advisory about Log4j2 vulnerabilities in Citrix Endpoint Management and Citrix Virtual Apps and Desktops.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Citrix has released and updated their advisory to address the Log4Shell vulnerabilities in Citrix Endpoint Management (Citrix XenMobile Server) and Citrix Virtual Apps and Desktops (XenApp & XenDesktop). An unauthenticated remote attacker could exploit these vulnerabilities to execute arbitrary code, cause a denial-of-service, and take control of affected systems.
NHS Digital response to Log4Shell
This alert is part of NHS Digital's wider response to the Log4Shell remote code execution vulnerability. For more information on Log4Shell itself, please visit our cyber alerts article Log4Shell RCE Vulnerability CC-3989.
Additional Citrix systems may be vulnerable and affected organisations should regularly review the Citrix Security Advisory for CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 and CVE-2021-44832. NHS and social care organisations are invited to use the Cyber Associates Network to find out additional information and participate in discussion about the Log4Shell remote code execution vulnerability and affected Citrix products.
Remediation advice
Affected organisations are encouraged to review the Citrix Security Advisory CTX335705 and review the Citrix support articles below and apply any necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
XenMobile Server 10.14 RP2 | CTX335763 https://support.citrix.com/article/CTX335763 |
| Patch |
XenMobile Server 10.14 RP3 | CTX335897 https://support.citrix.com/article/CTX335897 |
| Patch |
XenMobile Server 10.13 RP5 |CTX335753 https://support.citrix.com/article/CTX335753 |
| Patch |
XenMobile Server 10.13 RP6 |CTX335875 https://support.citrix.com/article/CTX335875 |
| Patch |
XenMobile Server 10.12 RP10 | CTX335785 https://support.citrix.com/article/CTX335785 |
| Patch |
XenMobile Server 10.12 RP11 | CTX335861 https://support.citrix.com/article/CTX335861 |
| Patch |
Citrix Virtual Apps and Desktops (XenApp & XenDesktop) https://support.citrix.com/article/CTX335705 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 5 January 2022 3:20 pm