|CERT-In Vulnerability Note
Security vulnerability in Citrix Workspace App
Original Issue Date:July 29, 2020
Severity Rating: HIGH
- Citrix Workspace app for Windows 1912 LTSR
- Citrix Workspace app for Windows 2002
A security vulnerability has been reported in Citrix Workspace App product for Windows which could allow a local user to escalate their privilege level or cause a remote attacker to perform arbitrary code execution.
This vulnerability exists in the Windows version of Citrix workspace app running updater service. An attacker could execute an arbitrary process under the SYSTEM account, by sending a crafted message over a named pipe and spoofing the client process ID. The vulnerability could be exploited if the application was installed with local or domain admin account and cause remote code execution if SMB is enabled and updater service is running.
Successful exploitation of this vulnerability could allow an attacker to escalate account privilege level or allow a remote attacker to perform arbitrary code execution.
Apply appropriate patches or workarounds as mentioned in
The information provided herein is on "as is" basis, without warranty of any kind.
Email: email@example.com Phone: +91-11-24368572
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
6, CGO Complex, Lodhi Road,
New Delhi - 110 003