Improper Privilege Vulnerability in Citrix Gateway Plug-in for Windows
CVE-2022-21827

7.1HIGH

Key Information:

Vendor
Citrix
Vendor
CVE Published:
26 May 2022

Summary

An improper privilege vulnerability has been identified in the Citrix Gateway Plug-in for Windows prior to version 21.9.1.2, which could allow an attacker with local access to manipulate or delete files with SYSTEM-level privileges. This vulnerability poses significant risks to the integrity and security of systems using the affected software, enabling malicious actors to exploit their access for harmful activities.

Affected Version(s)

Citrix Gateway Windows Plugin Citrix Gateway Plug-in for Windows versions before 21.9.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.