Citrix Security Updates – 12 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix Secure Access Client.

The addressed vulnerabilities could allow the attacker to execute arbitrary code or gain elevated privileges on the affected systems.

The addressed vulnerabilities:

1. Citrix Secure Access Client for Ubuntu Code Execution (CVE-2023-24492):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Citrix Secure Access Client for Windows Privilege Escalation (CVE-2023- 24491):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2023-24491
  • CVE-2023-24492
Mitigations

The enterprise should deploy this patch as soon as the testing phase is
completed.

Citrix Security Updates

References