CVE-2020-13885
published 2020-06-08CVE-2020-13885: Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.58%
45.4th percentile
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_workspace | — | — |
| citrix | citrix_workspace_app | — | — |
| citrix | workspace | — | — |
| citrix | workspace_app | < 2006.1 | 2006.1 |
| citrix | xenserver | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Vulnerabilities in Citrix Workspace app and Receiver for Windows
vendor_citrix·2020-06-11·CVSS 7.8
CVE-2020-13884 [HIGH] Vulnerabilities in Citrix Workspace app and Receiver for Windows
Vulnerabilities in Citrix Workspace app and Receiver for Windows
of Problem Vulnerabilities have been identified in Citrix Workspace app and Citrix Receiver for Windows that could result in a local user escalating their privilege level to administrator during the uninstallation process. The issues have the following identifiers: CVE-2020-13884 CVE-2020-13885 These vulnerabilities affect supported versions of Citrix Workspace app for Windows before 1912 and supported versions of Citrix Receiver for Windows. These vulnerabilities do not affect Citrix Workspace app and Receiver on any other platforms.
CVE References: CVE-2020-13884, CVE-2020-13885
Affected Products: Citrix Workspace app, XenServer, workspace
Severity: High
Remediation:
Citrix strongly recommends that customers upgrade to C
Citrix
CVE-2020-13885: Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the appl
vendor_citrix·2020-06-08·CVSS 7.8
CVE-2020-13885 [HIGH] CWE-276 CVE-2020-13885: Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the appl
CVE-2020-13885: Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
GHSA
GHSA-jgxx-8p2r-rf24: Citrix Workspace App before 2006
ghsa_unreviewed·2022-05-24
CVE-2020-13885 [HIGH] GHSA-jgxx-8p2r-rf24: Citrix Workspace App before 2006
Citrix Workspace App before 2006.1 on Windows has Insecure Permissions for "%PROGRAMDATA%\Citrix\Citrix Workspace ####\" which allows local users to gain privileges by copying a malicious webio.dll there.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-08
Published