CVE-2023-24486: Local user access to a system where another user is utilizing a vulnerable version of Citrix Workspace App for Linux to launch published desktops and applications
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24486?
CVE-2023-24486 is a vulnerability in Citrix Workspace app for Linux that allows a malicious local user to gain access to another user's Citrix Virtual Apps and Desktops session.
How does CVE-2023-24486 affect Citrix Workspace app for Linux?
CVE-2023-24486 allows a malicious local user to gain access to the Citrix Virtual Apps and Desktops session of another user on the same computer.
What is the severity of CVE-2023-24486?
CVE-2023-24486 has a severity rating of 5.5 (medium).
How can I fix CVE-2023-24486?
To fix CVE-2023-24486, update Citrix Workspace app for Linux to version 2302 or later.
Where can I find more information about CVE-2023-24486?
More information about CVE-2023-24486 can be found in the Citrix Workspace app for Linux security bulletin at https://support.citrix.com/article/CTX477618/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486.