CVE-2023-24492: Code Injection
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24492?
CVE-2023-24492 is a vulnerability discovered in the Citrix Secure Access client for Ubuntu, which could allow remote code execution.
How does CVE-2023-24492 work?
CVE-2023-24492 can be exploited when a victim user opens an attacker-crafted link and accepts further prompts, allowing the attacker to remotely execute code.
What is the severity of CVE-2023-24492?
CVE-2023-24492 has a severity rating of critical with a CVSS score of 8.8.
What versions of Citrix Secure Access client for Ubuntu are affected?
Versions up to exclusive 23.5.2 of Citrix Secure Access client for Ubuntu are affected by CVE-2023-24492.
How can I fix CVE-2023-24492?
To fix CVE-2023-24492, update your Citrix Secure Access client for Ubuntu to a version higher than 23.5.2.