← Vulnerability feed

Vulnerability record · CVE-2023-24485 · published 16 February 2023

CVE-2023-24485: Citrix workspace improper access control vulnerability

Citrix · Workspace

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

7.8 CVSS 3.1 High EPSS 0.22% · top 88.9% CWE-284 · Improper access controlCWE-863 · Incorrect authorization
7.8CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24485 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11634Citrix Workspace App for Windows improper access controlCitrix Workspace App before 1904 for Windows contains an improper access control flaw (CWE-284) that, per the CVSS vector, is remotely reachable with…KEVEPSS 8.0%analysed8.8CVE-2020-8207Citrix workspace improper access control vulnerabilityImproper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic upd…EPSS 2.1%8.5CVE-2024-6286Citrix workspace improper privilege management vulnerabilityLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for WindowsEPSS 0.39%7.8CVE-2022-21825Citrix workspace improper access control vulnerabilityAn Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacke…EPSS 0.22%7.8CVE-2021-22907Citrix workspace improper access control vulnerabilityAn improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2…EPSS 0.24%7.3CVE-2025-4879Citrix workspace improper privilege management vulnerabilityLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for WindowsEPSS 0.13%7.1CVE-2024-42423Citrix workspace incorrect authorization vulnerabilityCitrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogi…EPSS 0.15%7.0CVE-2024-7889Citrix workspace vulnerabilityLocal privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for WindowsEPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2023-24485), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.