← Vulnerability feed

Vulnerability record · CVE-2023-24491 · published 11 July 2023

CVE-2023-24491: Citrix secure access client improper privilege management vulnerability

Citrix · Secure Access Client

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.

7.8 CVSS 3.1 High EPSS 0.20% · top 90.9% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24491 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-24492Citrix secure access client code injection vulnerabilityA vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co…EPSS 0.88%8.6CVE-2025-0320Citrix secure access client improper privilege management vulnerabilityLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for WindowsEPSS 0.15%7.6CVE-2024-3661Fortinet forticlient missing authentication for critical function vulnerabilityDHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…EPSS 4.1%5.9CVE-2025-1222Citrix secure access client vulnerabilityAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for MacEPSS 0.16%5.9CVE-2025-1223Citrix secure access client uncontrolled search path element vulnerabilityAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for MacEPSS 0.16%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed7.8CVE-2026-21533Windows Remote Desktop improper privilege management allows local elevationWindows Remote Desktop contains an improper privilege management flaw (CWE-269) that lets an authorized attacker elevate privileges locally. It affec…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2023-24491), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.