CVE-2023-24491
published 2023-07-11CVE-2023-24491: A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adc | — | — |
| citrix | citrix_gateway | — | — |
| citrix | citrix_secure_access_client_for_windows | < 23.5.1.3 | 23.5.1.3 |
| citrix | secure_access_client | < 23.5.1.3 | 23.5.1.3 |
| citrix | xenserver | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwcp-whhw-8qj7: A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an en
ghsa_unreviewed·2023-07-12
CVE-2023-24491 [HIGH] CWE-269 GHSA-cwcp-whhw-8qj7: A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an en
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Citrix
Citrix Secure Access client for Windows Security Bulletin for CVE-2023-24491
vendor_citrix·2024-02-06·CVSS 7.8
CVE-2023-24491 [HIGH] CWE-269 Citrix Secure Access client for Windows Security Bulletin for CVE-2023-24491
Citrix Secure Access client for Windows Security Bulletin for CVE-2023-24491
Pre-requisites CWE CVE-2023-24491 Local Privilege escalation to NT AUTHORITY\SYSTEM Access to an endpoint with Standard User Account that has the vulnerable client installed CWE-269 Instructions This issue has been addressed in the following versions of the Citrix Secure Access client for Windows: 23.5.1.3 and later releases Citrix recommends that customers who are affected by the above vulnerability upgrade the Citrix Secure Access client for Windows installed on their endpoints by taking the following actions as soon as possible: If Citrix Secure Access client for Windows is distributed via the SSL VPN upgrade control feature of Citrix ADC or Citrix Gateway: Check the versions of the Citrix Secure Access client
Citrix
CVE-2023-24491:
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an
vendor_citrix·2023-07-11·CVSS 7.8
CVE-2023-24491 [HIGH] CWE-269 CVE-2023-24491:
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an
CVE-2023-24491:
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published