CVE-2025-1222
published 2025-02-20CVE-2025-1222: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
PriorityP432medium6.1CVSS 3.1
AVLACLPRLUINSUCHILAN
EPSS
0.15%
5.0th percentile
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | secure_access_client | < 25.01.2 | 25.01.2 |
| citrix | secure_access_client_for_mac | >= 25 < 01.2 | 01.2 |
| citrix | xenserver | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv4.05.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
CVE-2025-1222: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
vendor_citrix·2025-02-20·CVSS 6.1
CVE-2025-1222 [MEDIUM] CVE-2025-1222: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
CVE-2025-1222: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2025-02-11·CVSS 6.5
CVE-2025-21283 [MEDIUM] CWE-1222 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and user interaction is required (UI:R). What is the target context of the remote code execution?
Successful exploitation of this vulnerability requires the victim user to click a malicious link so that the attacker can initiate remote code execution on the renderer process.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
133.0.3065.51
2/6/2025
133.0.6943.53/54
Microsoft E
Citrix
Citrix Secure Access Client for Mac Security Bulletin for CVE-2025-1222 and CVE-2025-1223
vendor_citrix·CVSS 5.8
CVE-2025-1222 [MEDIUM] CWE-427 Citrix Secure Access Client for Mac Security Bulletin for CVE-2025-1222 and CVE-2025-1223
Citrix Secure Access Client for Mac Security Bulletin for CVE-2025-1222 and CVE-2025-1223
of Problem Vulnerabilities have been discovered in Citrix Secure Access Client for Mac. Refer to below for further details:
CVE References: CVE-2025-1222, CVE-2025-1223
Affected Products: XenServer
Severity: Medium
CVSS Score: 5.9
Remediation:
Cloud Software Group strongly urges customers of Citrix Secure Access Client for Mac to install the relevant updated versions as soon as possible: Citrix Secure Access Client for Mac 25.01.2 and later releases Workarounds/ Mitigating Factors None Acknowledgments Cloud Software Group thanks Mathieu Farrell of Quarkslab for working with us to protect Cloud Software Group customers.
GHSA
GHSA-mv3w-32c3-rrg8: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
ghsa_unreviewed·2025-02-20
CVE-2025-1222 [MEDIUM] GHSA-mv3w-32c3-rrg8: An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-20
Published