CVE-2024-7890: Local privilege escalation allows a low-privileged user to gain SYSTEM privileges
Published Sep 11, 2024
·Updated
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Affected Software
10 affected components
Citrix Workspace Windows<2203.1
Citrix Workspace Windows=2203.1-cu1
Citrix Workspace Windows=2203.1-cu2
Citrix Workspace Windows=2203.1-cu3
Citrix Workspace Windows=2203.1-cu4
Citrix Workspace Windows=2203.1-cu5
Citrix Workspace Windows=2203.1-cu6_hotfix1
Citrix Workspace Windows=2203.1-cu6_hotfix2
Citrix Workspace Windows=2402
Citrix Workspace Windows<2405
Event History
Sep 11, 2024
News Published
via The Register·01:27 AM
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
Description
Sep 15, 2024
News Published
via The Register·01:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-7890?
CVE-2024-7890 is classified as a high severity vulnerability due to its potential for local privilege escalation.
2
How do I fix CVE-2024-7890?
To remediate CVE-2024-7890, users should upgrade to the latest version of Citrix Workspace app for Windows that is not affected.
3
Who is affected by CVE-2024-7890?
CVE-2024-7890 affects low-privileged users of Citrix Workspace app for Windows versions up to 2203.1 and certain cumulative updates.
4
What kind of attack does CVE-2024-7890 enable?
CVE-2024-7890 allows a low-privileged user to escalate their privileges to SYSTEM, potentially compromising the host system.
5
Is there a known exploit for CVE-2024-7890?
As of now, there is no public information on specific exploits for CVE-2024-7890, but its nature suggests it could be targeted.