Junglewise Threat Intelligence

CVE-2019-11634: Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

CVE-2019-11634 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Citrix.

Executive brief

Citrix Workspace Application and Receiver for Windows contain a remote code execution vulnerability due to incorrect access control. The flaw exists because local drive access preferences are not properly enforced, potentially allowing unauthorized access to the client's local drives.

Affected products

  • Citrix Workspace App before 1904
  • Citrix Receiver for Windows 4.9 Cumulative Update 6 and earlier

Timeline

  • 2019-05-22: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog