CVE-2024-7889: Local privilege escalation allows a low-privileged user to gain SYSTEM privileges
Published Sep 11, 2024
·Updated
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Affected Software
10 affected components
Citrix Workspace Windows<2203.1
Citrix Workspace Windows=2203.1-cu1
Citrix Workspace Windows=2203.1-cu2
Citrix Workspace Windows=2203.1-cu3
Citrix Workspace Windows=2203.1-cu4
Citrix Workspace Windows=2203.1-cu5
Citrix Workspace Windows=2203.1-cu6_hotfix1
Citrix Workspace Windows=2203.1-cu6_hotfix2
Citrix Workspace Windows=2402
Citrix Workspace Windows<2405
Event History
Sep 11, 2024
News Published
via The Register·01:27 AM
CVE Published
via MITRE·10:16 PM
Data Sourced
via MITRE·10:16 PM
Description
Sep 15, 2024
News Published
via The Register·01:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-7889?
CVE-2024-7889 is classified as a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2024-7889?
To fix CVE-2024-7889, update the Citrix Workspace app for Windows to the latest version available.
3
Who is affected by CVE-2024-7889?
CVE-2024-7889 affects users of Citrix Workspace app for Windows versions up to 2203.1, including all update releases up to and including 2402.
4
What type of vulnerability is CVE-2024-7889?
CVE-2024-7889 is a local privilege escalation vulnerability that allows low-privileged users to gain SYSTEM privileges.
5
When was CVE-2024-7889 discovered?
CVE-2024-7889 was publicly disclosed in September 2024 as part of Citrix's security bulletins.