CERT-In Vulnerability Note
CIVN-2020-0305
Security vulnerability in Citrix Workspace App
Original Issue Date:July 29, 2020
Severity Rating: HIGH
Software Affected
- Citrix Workspace app for Windows 1912 LTSR
- Citrix Workspace app for Windows 2002
Overview
A security vulnerability has been reported in Citrix Workspace App product for Windows which could allow a local user to escalate their privilege level or cause a remote attacker to perform arbitrary code execution.
Description
This vulnerability exists in the Windows version of Citrix workspace app running updater service. An attacker could execute an arbitrary process under the SYSTEM account, by sending a crafted message over a named pipe and spoofing the client process ID. The vulnerability could be exploited if the application was installed with local or domain admin account and cause remote code execution if SMB is enabled and updater service is running.
Successful exploitation of this vulnerability could allow an attacker to escalate account privilege level or allow a remote attacker to perform arbitrary code execution.
Solution
Apply appropriate patches or workarounds as mentioned in
Citrix
Vendor Information
Citrix
https://support.citrix.com/article/CTX277662
References
SecurityWeek
https://www.securityweek.com/vulnerability-allows-remote-hacking-devices-running-citrix-workspace-app
PenTest Partners
https://www.pentestpartners.com/security-blog/raining-system-shells-with-citrix-workspace-app/
CVE Name
CVE-2020-8207
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|