CVE-2019-11634
KEV ransomwaremassAccess control flaw enabling RCE in Citrix Workspace App/Receiver for Windows
CISA: Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
CVE-2019-11634 is an incorrect access control flaw (CWE-284) in Citrix Workspace App and Receiver for Windows prior to version 1904. CISA classifies the impact as remote code execution, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates it can be triggered over the network without authentication or user interaction. A successful attacker gains code execution with high impact on the confidentiality, integrity, and availability of the affected Windows host. Any organization with endpoints running Citrix Workspace App or Receiver for Windows before 1904 is affected. The flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS estimates an 8% probability of exploitation within 30 days, so exploitation in the wild is established even though no public PoC is known.
What to do: Upgrade Citrix Workspace App for Windows to version 1904 or later per vendor instructions, and replace legacy Receiver for Windows installs with the updated Workspace App. Inventory endpoints for outdated Receiver/Workspace App versions and prioritize patching, given known ransomware use and the CISA KEV listing.
| Citrix Workspace App for Windows | all versions before 1904 |
| Citrix Receiver for Windows | all versions before 1904 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
- Affected
- Citrix Workspace Application and Receiver for Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- citrix
- Products
- receiver, workspace
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.