Improper Access Control in Citrix Workspace App for Windows
CVE-2021-22907

7.8HIGH

Key Information:

Vendor
Citrix
Vendor
CVE Published:
27 May 2021

Summary

An improper access control vulnerability in Citrix Workspace App for Windows could allow an attacker to escalate their privileges. This issue impacts versions prior to 2105 and the 1912 LTSR versions before CU4, thereby posing a risk to the application’s security framework. It is crucial for users to update to the latest versions to mitigate potential exploitation.

Affected Version(s)

Citrix Workspace App for Windows Citrix Workspace App for Windows 2105 and 1912 LTSR CU4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.