Citrix Product Security Update Advisory
Overview
An update has been released to address vulnerabilities in Citrix Products. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-6148, CVE-2024-6149
- Citrix Workspace app for HTML5 versions: ~ 2404.1 (excluded)
CVE-2024-7889, CVE-2024-7890
Current Release (CR)
- Citrix Workspace app for Windows versions: ~ 2405 (excluded)
Long Term Service Release (LTSR)
- Citrix Workspace app for Windows versions: ~ 2402 LTSR CU1 (excluded)
Resolved Vulnerabilities
GACS policy configuration setting bypass in the Citrix Workspace app for HTML5 (CVE-2024-6148)
Vulnerability in Citrix Workspace app for HTML5 that could redirect users to a vulnerable URL (CVE-2024-6149)
Local privilege escalation in the Citrix Workspace app for Windows that could allow a low-privileged user to gain SYSTEM privileges (CVE-2024-7889, CVE-2024-7890)
Vulnerability Patches
The following product-specific Vulnerability Patches have been made available in the latest update. If you are using an affected version, Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-6148, CVE-2024-6149
- Citrix Workspace app for HTML5 versions: 2404.1 or later version
CVE-2024-7889, CVE-2024-7890
Current Release (CR)
- Citrix Workspace app for Windows versions: 2405 or later version
Long Term Service Release (LTSR)
- Citrix Workspace app for Windows versions: 2402 LTSR CU1 or later version
Referenced Sites
[1] Citrix Workspace app for HTML5 Security Bulletin CVE-2024-6148 and CVE-2024-6149
[2] Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890