Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/94460
http://www.securitytracker.com/id/1030566
http://www.securityfocus.com/bid/68530
http://secunia.com/advisories/59889
http://support.citrix.com/article/CTX139591
Source: Mitre, NVD
Published: 2014-07-11
Updated: 2025-04-12
Base Score: 4.9
Vector: CVSS2#AV:A/AC:M/Au:S/C:P/I:P/A:P
Severity: Medium
Base Score: 7.1
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity: High
EPSS: 0.00251