Executive brief
Citrix Workspace Application and Receiver for Windows contain a remote code execution vulnerability due to incorrect access control. The flaw exists because local drive access preferences are not properly enforced, potentially allowing unauthorized access to the client's local drives.
Affected products
- Citrix Workspace App before 1904
- Citrix Receiver for Windows 4.9 Cumulative Update 6 and earlier
Timeline
- 2019-05-22: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog