CVE-2022-21827

7.1HIGH

Key Information

Vendor
Citrix
Status
Citrix Gateway Windows Plugin
Vendor
CVE Published:
26 May 2022

Summary

An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.

Affected Version(s)

Citrix Gateway Windows Plugin = Citrix Gateway Plug-in for Windows versions before 21.9.1.2

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.