HomeSecurityCitrix warns of vulnerabilities in Workspace for Windows

Citrix warns of vulnerabilities in Workspace for Windows

Citrix is ​​warning of two vulnerabilities in the Citrix Workspace app for Windowsthat could allow attackers to gain elevated privileges on vulnerable systems.

Citrix Workspace Windows vulnerabilities

The vulnerabilities are tracked as CVE-2024-7889 and CVE-2024-7890 . They allow local privilege escalation, which could allow attackers to gain SYSTEM-level access

Affected versions

Current Release (CR) users: The vulnerabilities affect all versions of Citrix Workspace for Windows prior to 2405.

Long Term Service Release (LTSR) users: Versions prior to 2402 LTSR CU1 are vulnerable to both vulnerabilities.

Users should verify software and apply necessary updates as soon as they become available.

See also: Apple fixes 'GAZEploit' vulnerability in Vision Pro

Citrix Workspace: Details on the two vulnerabilities

CVE-2024-7889

CVE-2024-7889 is a local privilege escalation vulnerability, which allows a low-privileged user to gain SYSTEM privileges.

The vulnerability has received a CVSS v4.0 score of 7/10. For an attack, local access to the target system is required. However, it can cause a major problem.

See also: Cisco IOS XR vulnerability allows hackers to gain elevated privileges

CVE-2024-7890

Another local privilege escalation vulnerability, which also allows for SYSTEM privileges. With a CVSS v4.0 score of 5.4/10, this vulnerability is less severe than CVE-2024-7889, but still poses a significant threat. Again, local access to the system is required.

Citrix has provided updates that address these security issues and urges users to update their Citrix Workspace app to the latest versions.

Citrix warns of vulnerabilities in Workspace for Windows

It is imperative for organizations to prioritize the security of their systems, especially when using applications, such as Citrix Workspace, that handle sensitive data. Regularly updating software and implementing strong security practices are essential to prevent potential attacks and minimize damage in the event of a breach.

See also: Adobe fixes zero-day vulnerability in Acrobat Reader (with PoC exploit)

In addition to addressing vulnerabilities and providing updates, Citrix has also emphasized the importance of educating users on cybersecurity best practices. This includes exercising caution when opening email attachments or clicking on suspicious links, as well as regularly changing passwords and using strong, unique passwords.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

By taking a proactive approach and staying informed about potential security risks, organizations can ensure the security of their systems and maintain the trust of their customers.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS