CVE-2013-6077: Citrix Xendesktop

Medium severity, CVSS 5.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.

Affected products

  • Citrix Xendesktop: version 7.0 only

Published 2013-11-05. Last modified 2026-06-16.