CVE-2020-13884
published 2020-06-08CVE-2020-13884: Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
45.1th percentile
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_workspace | — | — |
| citrix | citrix_workspace_app | — | — |
| citrix | workspace | — | — |
| citrix | workspace_app | < 2006.1 | 2006.1 |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Vulnerabilities in Citrix Workspace app and Receiver for Windows
vendor_citrix·2020-06-11·CVSS 7.8
CVE-2020-13884 [HIGH] Vulnerabilities in Citrix Workspace app and Receiver for Windows
Vulnerabilities in Citrix Workspace app and Receiver for Windows
of Problem Vulnerabilities have been identified in Citrix Workspace app and Citrix Receiver for Windows that could result in a local user escalating their privilege level to administrator during the uninstallation process. The issues have the following identifiers: CVE-2020-13884 CVE-2020-13885 These vulnerabilities affect supported versions of Citrix Workspace app for Windows before 1912 and supported versions of Citrix Receiver for Windows. These vulnerabilities do not affect Citrix Workspace app and Receiver on any other platforms.
CVE References: CVE-2020-13884, CVE-2020-13885
Affected Products: Citrix Workspace app, XenServer, workspace
Severity: High
Remediation:
Citrix strongly recommends that customers upgrade to C
Citrix
CVE-2020-13884: Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges du
vendor_citrix·2020-06-08·CVSS 7.8
CVE-2020-13884 [HIGH] CWE-276 CVE-2020-13884: Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges du
CVE-2020-13884: Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
GHSA
GHSA-j7f2-25g8-8gjg: Citrix Workspace App before 2006
ghsa_unreviewed·2022-05-24
CVE-2020-13884 [HIGH] GHSA-j7f2-25g8-8gjg: Citrix Workspace App before 2006
Citrix Workspace App before 2006.1 on Windows has Insecure Permissions for %PROGRAMDATA%\Citrix (and an unquoted UninstallString), which allows local users to gain privileges by copying a malicious citrix.exe there.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-08
Published