CVE-2021-22907

HIGH

Citrix Workspace App for Windows < 2105 and 1912 LTSR < CU4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.citrix.com/article/CTX307794

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 31.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (2)
citrix/workspace < 19.12.4000
citrix/workspace < 2105
Published May 27, 2021
Tracked Since Feb 18, 2026