Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-13884
Citrix Workspace App vulnerability analysis and mitigation

Overview

Citrix Workspace App before version 1912 on Windows contains an Insecure Permissions and Unquoted Path vulnerability identified as CVE-2020-13884. The vulnerability was discovered on February 10, 2020, and was publicly disclosed in June 2020. This security flaw affects the Windows versions of Citrix Workspace App prior to version 1912 and the legacy Citrix Receiver product (GitHub POC, Citrix Advisory).

Technical details

The vulnerability stems from two key issues: insecure permissions on the %PROGRAMDATA%\Citrix directory that allows write access to regular users, and an unquoted UninstallString path in the Windows registry at HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CitrixOnlinePluginPackWeb. The vulnerability has received a CVSS v3.1 score of 7.8 (HIGH) (NVD).

Impact

When exploited, this vulnerability allows local users to gain elevated system privileges during the uninstallation process of the application. The impact is particularly significant as it provides attackers with the ability to escalate their privileges to system level, potentially gaining full control over the affected system (GitHub POC).

Exploitability

The vulnerability can be exploited by copying a malicious citrix.exe file to C:\ProgramData\Citrix directory. The malicious code is then executed with elevated privileges when an administrator or software distribution system initiates the uninstallation of Citrix Workspace app (GitHub POC).

Mitigation and workarounds

The vulnerability has been addressed in Citrix Workspace App version 1912 and later releases. Organizations using affected versions should upgrade to version 1912 or newer to mitigate this security risk. Citrix has also recommended users of the legacy Receiver product to migrate to the newer Workspace app (Citrix Advisory).

Additional resources


SourceThis report was generated using AI

Related Citrix Workspace App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-13885HIGH7.8
  • Citrix Workspace App logoCitrix Workspace App
  • cpe:2.3:a:citrix:workspace_app
NoYesJun 08, 2020
CVE-2020-13884HIGH7.8
  • Citrix Workspace App logoCitrix Workspace App
  • cpe:2.3:a:citrix:workspace_app
NoYesJun 08, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management