CVE-2014-4700: Citrix Xendesktop

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.

Affected products

  • Citrix Xendesktop: from 5.0, up to and including 5.6; from 7.0, up to and including 7.11; version 4.0 only; version 5.6 only

Published 2014-07-11. Last modified 2026-06-17.