QID 377990

Date Published: 2023-02-16

QID 377990: Citrix Workspace App For Linux Session Takeover Vulnerability (CTX477618)

A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.

Affected Versions:
This issue affects all supported versions of Citrix Workspace app for Linux before 2302

QID detection logic (Authenticated):
This QID checks for vulnerable version of Citrix Workspace app for Linux by checking the version from installed packages.

Successful exploitation of the vulnerability may allow local user to escalate privileges and take over session of a high privileged user.

  • CVSS V3 rated as Critical - 8.4 severity.
  • CVSS V2 rated as High - 6.2 severity.
  • Solution
    Vendor has relased patch, customers are advised to upgrade to Citrix Workspace app for Linux 2302 and later. For more information, please refer to CTX477618

    CVEs related to QID 377990

    Software Advisories
    Advisory ID Software Component Link
    CTX477618 URL Logo support.citrix.com/article/CTX477618/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486