ZeroHour

CVE-2019-11634

KEV ransomwaremass

Access control flaw enabling RCE in Citrix Workspace App/Receiver for Windows

CISA: Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2019-11634 is an incorrect access control flaw (CWE-284) in Citrix Workspace App and Receiver for Windows prior to version 1904. CISA classifies the impact as remote code execution, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates it can be triggered over the network without authentication or user interaction. A successful attacker gains code execution with high impact on the confidentiality, integrity, and availability of the affected Windows host. Any organization with endpoints running Citrix Workspace App or Receiver for Windows before 1904 is affected. The flaw was added to CISA's KEV on 2021-11-03 with known ransomware use, and EPSS estimates an 8% probability of exploitation within 30 days, so exploitation in the wild is established even though no public PoC is known.

What to do: Upgrade Citrix Workspace App for Windows to version 1904 or later per vendor instructions, and replace legacy Receiver for Windows installs with the updated Workspace App. Inventory endpoints for outdated Receiver/Workspace App versions and prioritize patching, given known ransomware use and the CISA KEV listing.

Affected
Citrix Workspace App for Windowsall versions before 1904
Citrix Receiver for Windowsall versions before 1904
Estimated exposure
masson the order of 1M-10M Windows endpoints — Citrix Receiver/Workspace App is the standard endpoint client for Citrix Virtual Apps and Desktops, one of the most widely deployed enterprise remote-access client bases, so the vulnerable pre-1904 population plausibly exceeds one million…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

CISA Known Exploited Vulnerability
Affected
Citrix Workspace Application and Receiver for Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
citrix
Products
receiver, workspace
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.