← Vulnerability feed

Vulnerability record · CVE-2025-0320 · published 17 June 2025

CVE-2025-0320: Citrix secure access client improper privilege management vulnerability

Citrix · Secure Access Client

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows

8.6 CVSS 4.0 High EPSS 0.15% · top 96.8% CWE-269 · Improper privilege management
8.6CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0320 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-24492Citrix secure access client code injection vulnerabilityA vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co…EPSS 0.88%7.8CVE-2023-24491Citrix secure access client improper privilege management vulnerabilityA vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an end…EPSS 0.20%7.6CVE-2024-3661Fortinet forticlient missing authentication for critical function vulnerabilityDHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…EPSS 4.1%5.9CVE-2025-1222Citrix secure access client vulnerabilityAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for MacEPSS 0.16%5.9CVE-2025-1223Citrix secure access client uncontrolled search path element vulnerabilityAn attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for MacEPSS 0.16%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed7.8CVE-2026-21533Windows Remote Desktop improper privilege management allows local elevationWindows Remote Desktop contains an improper privilege management flaw (CWE-269) that lets an authorized attacker elevate privileges locally. It affec…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2025-0320), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.