← Vulnerability feed

Vulnerability record · CVE-2019-11634 · published 22 May 2019

CVE-2019-11634: Citrix Workspace App for Windows improper access control

Citrix · Receiver

Citrix Workspace App before 1904 for Windows contains an improper access control flaw (CWE-284) that, per the CVSS vector, is remotely reachable without authentication or user interaction. The record gives no further technical detail on the vulnerable component or mechanism, but the impact is rated total across confidentiality, integrity and availability.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 8.0% · top 5.4% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 7.5
8.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
12 Aug 2026Last modified by NVD

Description

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, plus CISA KEV listing and documented ransomware use, make this a top remediation priority.

What it is

Citrix Workspace App before 1904 for Windows contains an improper access control flaw (CWE-284) that, per the CVSS vector, is remotely reachable without authentication or user interaction. The record gives no further technical detail on the vulnerable component or mechanism, but the impact is rated total across confidentiality, integrity and availability.

Impact

An unauthenticated remote attacker can achieve full compromise of confidentiality, integrity and availability on the affected host, consistent with the CISA KEV listing as a remote code execution vulnerability.

Attack surface

Network-reachable per the CVSS vector (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required. The record does not specify the exact protocol or service exposed, so the precise entry point cannot be confirmed from the supplied data.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability of 0.08026 (94th percentile), indicating observed exploitation in the wild. All references are vendor advisories and the CISA KEV entry; no public exploit code is cited in the record.

What to do

  • Upgrade Citrix Workspace App for Windows to 1904 or later per the vendor advisory CTX251986.
  • If immediate upgrade is not possible, restrict network exposure of the affected client and limit access to trusted hosts.
  • Apply the vendor's required action from the CISA KEV entry and track remediation against the 2022-05-03 due date.
  • Inventory endpoints for Citrix Workspace App and Receiver for Windows versions below 1904 and prioritize them for patching.
  • Monitor for post-exploitation activity on hosts running the affected client, given documented ransomware use.

Detection

  • Query endpoint inventory for Citrix Workspace App or Receiver for Windows versions older than 1904.
  • Alert on unexpected child processes or network connections spawned by Citrix Workspace App or Receiver processes.
  • Correlate host telemetry with ransomware indicators on systems running the affected client.
  • Review network logs for anomalous inbound connections to endpoints hosting the affected client.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-11634 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-8207Citrix workspace improper access control vulnerabilityImproper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…EPSS 2.1%8.5CVE-2024-6286Citrix workspace improper privilege management vulnerabilityLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for WindowsEPSS 0.39%7.8CVE-2023-24485Citrix workspace improper access control vulnerabilityVulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…EPSS 0.22%7.8CVE-2022-21825Citrix workspace improper access control vulnerabilityAn Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacke…EPSS 0.22%7.8CVE-2021-22907Citrix workspace improper access control vulnerabilityAn improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2…EPSS 0.24%7.8CVE-2012-4603Citrix receiver improper input validation vulnerabilityCitrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute ar…EPSS 6.9%7.3CVE-2025-4879Citrix workspace improper privilege management vulnerabilityLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for WindowsEPSS 0.13%7.1CVE-2024-42423Citrix workspace incorrect authorization vulnerabilityCitrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogi…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2019-11634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.