CVE-2023-24485: Privilege Escalation on the system running a vulnerable version of Citrix Workspace app for Windows
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-24485?
CVE-2023-24485 is a vulnerability that allows a standard Windows user to perform operations as SYSTEM on a computer running Citrix Workspace app.
Which versions of Citrix Workspace app are affected by CVE-2023-24485?
CVE-2023-24485 affects Citrix Workspace app versions 1912, 2203.1, and their respective cumulative updates (cu1, cu2, cu3, cu4, cu5, cu6).
What is the severity of CVE-2023-24485?
CVE-2023-24485 has a severity rating of 7.8, classified as high.
How can I fix CVE-2023-24485?
To mitigate CVE-2023-24485, it is recommended to update Citrix Workspace app to the latest version or apply the corresponding security patches.
Where can I find more information about CVE-2023-24485?
More information about CVE-2023-24485 can be found on the Citrix support website: https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485