Vulnerabilities > Citrix > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-11 CVE-2023-24491 Unspecified vulnerability in Citrix Secure Access Client
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
local
low complexity
citrix
7.8
2023-07-11 CVE-2023-24492 Code Injection vulnerability in Citrix Secure Access Client
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
network
low complexity
citrix CWE-94
8.8
2023-07-10 CVE-2023-24487 Unspecified vulnerability in Citrix Application Delivery Controller and Gateway
Arbitrary file read in Citrix ADC and Citrix Gateway?
network
low complexity
citrix
7.5
2023-02-16 CVE-2023-24483 Improper Privilege Management vulnerability in Citrix Virtual Apps and Desktops
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
local
low complexity
citrix CWE-269
7.8
2023-02-16 CVE-2023-24485 Incorrect Authorization vulnerability in Citrix Workspace 1912/2105/2203.1
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
local
low complexity
citrix CWE-863
7.8
2023-01-26 CVE-2022-27508 Resource Exhaustion vulnerability in Citrix Application Delivery Controller and Gateway
Unauthenticated denial of service
network
low complexity
citrix CWE-400
7.5
2022-06-16 CVE-2022-27511 Unspecified vulnerability in Citrix Application Delivery Management
Corruption of the system by a remote, unauthenticated user.
network
high complexity
citrix
8.1
2022-04-19 CVE-2021-44519 Path Traversal vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
network
low complexity
citrix CWE-22
8.8
2022-04-13 CVE-2022-26151 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
network
low complexity
citrix CWE-77
7.2
2022-02-09 CVE-2022-21825 Unspecified vulnerability in Citrix Workspace
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
local
low complexity
citrix
7.8