• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – Siemens SIMATIC Panels and WinCC (TIA Portal) Multiple Vulnerabilities
May 16, 2019
Rewterz Threat Advisory – CVE-2019-11114 – Intel Driver Support & Assistance – Local Privilege Escalation Vulnerability
May 16, 2019

Rewterz Threat Advisory – CVE-2019-11634 – Citrix Workspace / Receiver for Windows Remote Code Execution Vulnerability

May 16, 2019

Severity

Medium

Analysis Summary

A vulnerability has been identified in Citrix Workspace app and Receiver (for Windows only) that could result in local drive access preferences not being enforced allowing an attacker read/write access to the clients local drives which could enable code execution on the client device. 

The vulnerability allows bypass of the general user authentication normally required to allow read/write access. When it’s exploited via Microsoft Edge and Microsoft Internet Explorer, there is zero interaction required in all cases. Whereas exploitation via Google Chrome and Mozilla Firefox may require a single user click depending on configuration.

Impact

  • Data Exfiltration
  • Remote Code Execution

Affected Vendors

Citrix

Affected Products

Citrix Workspace App versions prior to 1904
Receiver for Windows versions prior to LTSR 4.9 CU6 version 4.9.6001

Remediation

Upgrade Citrix Workspace app to version 1904 or later and Receiver for Windows to LTSR 4.9 CU6 version 4.9.6001.

The new Citrix Workspace app version is available from the following Citrix website location:

https://www.citrix.com/downloads/workspace-app/

The new LTSR version is available from the following Citrix website location:

https://www.citrix.com/downloads/citrix-receiver/windows-ltsr/receiver-for-windows-ltsr-latest.html

  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.