
Cloud Vulnerability DB
A community-led vulnerabilities database
Citrix Workspace App before version 1912 on Windows contains a security vulnerability identified as CVE-2020-13885. The vulnerability was discovered on February 10, 2020, and involves insecure permissions that could allow local users to gain elevated privileges during the application's uninstallation process. This security flaw specifically affects Windows installations of Citrix Workspace App versions prior to 1912 (GitHub POC, NVD).
The vulnerability stems from insecure permissions set for the directory '%PROGRAMDATA%\Citrix\Citrix Workspace ####'. This security flaw has been assigned a CVSS v3.1 score of 8.8 (HIGH) and a CVSS v2.0 score of 6.0 (MEDIUM). The technical nature of the vulnerability allows local users to exploit the insecure permissions by placing a malicious webio.dll file in the affected directory (GitHub POC, NVD).
When successfully exploited, this vulnerability enables local users to escalate their privileges to system level access. The impact becomes particularly significant during the uninstallation process of the Citrix Workspace app, as it can lead to the execution of malicious code with elevated privileges (GitHub POC).
The exploitation process involves dropping a malicious webio.dll file to the vulnerable directory ('%PROGRAMDATA%\Citrix\Citrix Workspace 1911'). The malicious code is then executed when an administrator or software distribution system initiates the uninstallation of the Citrix Workspace app (GitHub POC).
The vulnerability has been addressed in Citrix Workspace App version 1912 and later releases. Users and organizations running affected versions are strongly advised to upgrade to version 1912 or newer to mitigate this security risk (Citrix Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."