Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-13885
Citrix Workspace App vulnerability analysis and mitigation

Overview

Citrix Workspace App before version 1912 on Windows contains a security vulnerability identified as CVE-2020-13885. The vulnerability was discovered on February 10, 2020, and involves insecure permissions that could allow local users to gain elevated privileges during the application's uninstallation process. This security flaw specifically affects Windows installations of Citrix Workspace App versions prior to 1912 (GitHub POC, NVD).

Technical details

The vulnerability stems from insecure permissions set for the directory '%PROGRAMDATA%\Citrix\Citrix Workspace ####'. This security flaw has been assigned a CVSS v3.1 score of 8.8 (HIGH) and a CVSS v2.0 score of 6.0 (MEDIUM). The technical nature of the vulnerability allows local users to exploit the insecure permissions by placing a malicious webio.dll file in the affected directory (GitHub POC, NVD).

Impact

When successfully exploited, this vulnerability enables local users to escalate their privileges to system level access. The impact becomes particularly significant during the uninstallation process of the Citrix Workspace app, as it can lead to the execution of malicious code with elevated privileges (GitHub POC).

Exploitability

The exploitation process involves dropping a malicious webio.dll file to the vulnerable directory ('%PROGRAMDATA%\Citrix\Citrix Workspace 1911'). The malicious code is then executed when an administrator or software distribution system initiates the uninstallation of the Citrix Workspace app (GitHub POC).

Mitigation and workarounds

The vulnerability has been addressed in Citrix Workspace App version 1912 and later releases. Users and organizations running affected versions are strongly advised to upgrade to version 1912 or newer to mitigate this security risk (Citrix Support).

Additional resources


SourceThis report was generated using AI

Related Citrix Workspace App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-13885HIGH7.8
  • Citrix Workspace App logoCitrix Workspace App
  • cpe:2.3:a:citrix:workspace_app
NoYesJun 08, 2020
CVE-2020-13884HIGH7.8
  • Citrix Workspace App logoCitrix Workspace App
  • cpe:2.3:a:citrix:workspace_app
NoYesJun 08, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management