← Vulnerability feed

Vulnerability record · CVE-2008-2299 · published 18 May 2008

CVE-2008-2299: Citrix presentation server vulnerability

Citrix · Presentation Server

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions.

5.0 CVSS 2.0 Medium EPSS 1.1% · top 36.6% CWE-310 · CWE-310
5.0CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2299 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0356Citrix Presentation Server IMA Service Buffer OverflowThe Independent Management Architecture (IMA) service in Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop S…EPSS 73%analysed10.0CVE-2007-2850Citrix access essentials vulnerabilityThe Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows…EPSS 2.8%7.5CVE-2009-2453Citrix presentation server permissions and access controls vulnerabilityCitrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…EPSS 1.4%6.8CVE-2008-4676Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti…EPSS 0.29%6.5CVE-2008-2300Citrix access essentials permissions and access controls vulnerabilityUnspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo…EPSS 1.4%6.5CVE-2006-3779Citrix metaframe vulnerabilityCitrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remot…EPSS 1.3%4.3CVE-2002-2426Citrix access essentials cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1…EPSS 0.66%1.9CVE-2008-5107Citrix desktop server information exposure vulnerabilityThe installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI l…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2008-2299), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.