A vulnerability has been identified in Citrix Workspace app and Receiver (for Windows only) that could result in local drive access preferences not being enforced allowing an attacker read/write access to the clients local drives which could enable code execution on the client device.
The vulnerability allows bypass of the general user authentication normally required to allow read/write access. When it’s exploited via Microsoft Edge and Microsoft Internet Explorer, there is zero interaction required in all cases. Whereas exploitation via Google Chrome and Mozilla Firefox may require a single user click depending on configuration.
Citrix Workspace App versions prior to 1904
Receiver for Windows versions prior to LTSR 4.9 CU6 version 4.9.6001
Upgrade Citrix Workspace app to version 1904 or later and Receiver for Windows to LTSR 4.9 CU6 version 4.9.6001.
The new Citrix Workspace app version is available from the following Citrix website location:
The new LTSR version is available from the following Citrix website location: