Citrix Security Update – 11 September 2024

Citrix has released a security update to address multiple vulnerabilities across Citrix Workspace app for Windows.

The addressed vulnerabilities could allow the attacker to gain elevated privileges to the affected systems by sending a specially crafted request.

The addressed vulnerabilities:

1. Citrix Workspace app for Windows Privilege Escalation Vulnerability (CVE-2024-7889):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

2. Citrix Workspace app for Windows Privilege Escalation Vulnerability (CVE-2024-7890):

  • CVSS: 6.7
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2024-7889
  • CVE-2024-7890
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Citrix Security Update

References