CVE-2012-6314: Citrix Xendesktop

Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.

Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device.

Affected products

  • Citrix Xendesktop: version 5.6 only

Published 2012-12-26. Last modified 2026-06-16.