Citrix Workspace App for Windows Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in Citrix Workspace app for Windows. This issue allows a low-privileged user to gain SYSTEM privileges. The vulnerability affects the Current Release (CR) versions prior to 2409, as well as Long Term Service Release (LTSR) versions prior to 2402 LTSR CU2 Hotfix 1 and 2402 LTSR CU3 Hotfix 1. The vulnerability requires local access to the target system and the App Protection service to be running.

Impact

Exploitation of this vulnerability allows low-privileged users to elevate their privileges to SYSTEM level.

Remediation

Users are advised to upgrade to Citrix Workspace app for Windows versions 2409 and later. For Long Term Service Release (LTSR) users, versions 2402 LTSR CU2 Hotfix 1 and 2402 LTSR CU3 Hotfix 1 and later are recommended.

Added: Jun 17, 2025, 2:17 PM
Updated: Jun 17, 2025, 2:17 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
2.9
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.