
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN338
_____________________________________________________________________

DATE                : 11/06/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows running Citrix Workspace app and Receiver
                                  versions prior to 1912.

=====================================================================
https://support.citrix.com/article/CTX275460
_____________________________________________________________________

CTX275460
Vulnerabilities in Citrix Workspace app and Receiver for Windows
Security Bulletin | High | 2 found this helpful | Created: 11 Jun 2020 |
Modified: 11 Jun 2020


Applicable Products

    Receiver for Windows
    Citrix Workspace App


Description of Problem

Vulnerabilities have been identified in Citrix Workspace app and
Receiver for Windows that could result in a local user escalating their
privilege level to administrator during the uninstallation process.

The issues have the following identifiers:

    CVE-2020-13884

    CVE-2020-13885

These vulnerabilities affect supported versions of Citrix Workspace app
for Windows before 1912 and all supported versions of Citrix Receiver
for Windows.

These vulnerabilities do not affect Citrix Workspace app and Receiver on
any other platforms.


What Customers Should Do

A new version of Citrix Workspace app for Windows has been released.
Citrix strongly recommends that customers upgrade Citrix Workspace app
to version 1912 or later via Auto Update, or by directly running the
installer. Customers using Citrix Receiver are strongly recommended to
upgrade to Citrix Workspace app.

The new Citrix Workspace app version is available from the following
Citrix website location:

https://www.citrix.com/downloads/workspace-app/

The new LTSR version is available from the following Citrix website
location:

https://www.citrix.com/downloads/workspace-app/workspace-app-for-windows-long-term-service-release/workspace-app-for-windows-1912ltsr.html


Acknowledgements

Citrix would like to thank Andrew Hess for working with us to protect
Citrix customers.


What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential
security issue. This article is also available from the Citrix Knowledge
Center at  http://support.citrix.com/.


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at  https://www.citrix.com/support/open-a-support-case.html.


Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For details
on our vulnerability response process and guidance on how to report
security-related issues to Citrix, please visit the Citrix Trust Center
at https://www.citrix.com/about/trust-center/vulnerability-process.html.


Changelog

Date            Change
2020-06-11 	Initial Publication


=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================



