Vulnerability record · CVE-2019-11634 · published 22 May 2019
CVE-2019-11634: Citrix Workspace App for Windows improper access control
Citrix · Receiver
Citrix Workspace App before 1904 for Windows contains an improper access control flaw (CWE-284) that, per the CVSS vector, is remotely reachable without authentication or user interaction. The record gives no further technical detail on the vulnerable component or mechanism, but the impact is rated total across confidentiality, integrity and availability.
Description
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus CISA KEV listing and documented ransomware use, make this a top remediation priority.
What it is
Citrix Workspace App before 1904 for Windows contains an improper access control flaw (CWE-284) that, per the CVSS vector, is remotely reachable without authentication or user interaction. The record gives no further technical detail on the vulnerable component or mechanism, but the impact is rated total across confidentiality, integrity and availability.
Impact
An unauthenticated remote attacker can achieve full compromise of confidentiality, integrity and availability on the affected host, consistent with the CISA KEV listing as a remote code execution vulnerability.
Attack surface
Network-reachable per the CVSS vector (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required. The record does not specify the exact protocol or service exposed, so the precise entry point cannot be confirmed from the supplied data.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability of 0.08026 (94th percentile), indicating observed exploitation in the wild. All references are vendor advisories and the CISA KEV entry; no public exploit code is cited in the record.
What to do
- Upgrade Citrix Workspace App for Windows to 1904 or later per the vendor advisory CTX251986.
- If immediate upgrade is not possible, restrict network exposure of the affected client and limit access to trusted hosts.
- Apply the vendor's required action from the CISA KEV entry and track remediation against the 2022-05-03 due date.
- Inventory endpoints for Citrix Workspace App and Receiver for Windows versions below 1904 and prioritize them for patching.
- Monitor for post-exploitation activity on hosts running the affected client, given documented ransomware use.
Detection
- Query endpoint inventory for Citrix Workspace App or Receiver for Windows versions older than 1904.
- Alert on unexpected child processes or network connections spawned by Citrix Workspace App or Receiver processes.
- Correlate host telemetry with ransomware indicators on systems running the affected client.
- Review network logs for anomalous inbound connections to endpoints hosting the affected client.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-11634 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11634 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.