This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
This signature detects the attempt to execute arbitrary code on the device.
Citrix Workspace App and Receiver for Windows are prone to a remote code-execution vulnerability. Specifically, this issue occurs due to insufficient access permissions enforcement on local drive access. An attacker can exploit this issue to gain read/write access to the clients local drives.
Successfully exploiting this issue will allow attackers to execute arbitrary code on the device.
- The following products are vulnerable:
- Citrix Workspace App for Windows versions prior to 1904 are vulnerable.
- Citrix Receiver for Windows version LTSR 4.9 CU6 is vulnerable.