9.8
CVE-2019-11634
- EPSS 8.03%
- Veröffentlicht 22.05.2019 17:29:00
- Zuletzt bearbeitet 12.08.2026 05:17:21
- CVE-Watchlists
- Unerledigt
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
SchwachstelleCitrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.03% | 0.942 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://support.citrix.com/article/CTX251986
https://support.citrix.com/v1/search?searchQuery=%22%22&lang=en&sort=cr_date_desc&prod=&pver=&ct=Security+Bulletin
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11634