Total
11 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-24486 | 1 Citrix | 1 Workspace | 2024-10-25 | N/A | 5.5 MEDIUM |
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | |||||
CVE-2024-7890 | 1 Citrix | 1 Workspace | 2024-10-22 | N/A | 7.3 HIGH |
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |||||
CVE-2024-7889 | 1 Citrix | 1 Workspace | 2024-10-22 | N/A | 7.3 HIGH |
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |||||
CVE-2024-42423 | 2 Citrix, Dell | 2 Workspace, Thinos | 2024-09-20 | N/A | 7.1 HIGH |
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering. | |||||
CVE-2024-6148 | 1 Citrix | 1 Workspace | 2024-09-05 | N/A | 8.8 HIGH |
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 | |||||
CVE-2023-24484 | 1 Citrix | 1 Workspace | 2024-02-28 | N/A | 5.5 MEDIUM |
A malicious user can cause log files to be written to a directory that they do not have permission to write to. | |||||
CVE-2023-24485 | 1 Citrix | 1 Workspace | 2024-02-28 | N/A | 7.8 HIGH |
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | |||||
CVE-2022-21825 | 1 Citrix | 1 Workspace | 2024-02-28 | 4.6 MEDIUM | 7.8 HIGH |
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. | |||||
CVE-2021-22907 | 1 Citrix | 1 Workspace | 2024-02-28 | 7.2 HIGH | 7.8 HIGH |
An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. | |||||
CVE-2020-8207 | 1 Citrix | 1 Workspace | 2024-02-28 | 6.0 MEDIUM | 8.8 HIGH |
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. | |||||
CVE-2019-11634 | 1 Citrix | 2 Receiver, Workspace | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
Citrix Workspace App before 1904 for Windows has Incorrect Access Control. |