
=====================================================================

                           CERT-Renater

                 Note d'Information No. 2022/VULN015
_____________________________________________________________________

DATE                : 13/01/2022

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running CitrixWorkspace App

=====================================================================
https://support.citrix.com/article/CTX338435
_____________________________________________________________________

Applicable Products
Citrix Workspace App
Description of Problem
A vulnerability has been identified in Citrix Workspace app for Linux
that could result in a local user elevating their privilege level to
root on the computer running Citrix Workspace app for Linux.

The vulnerability has the following identifier:

CVE ID

Description

Vulnerability Type

Pre-conditions

CVE-2022-21825

Local privilege Escalation

CWE-284: Improper Access Control

Local user access to a system where Citrix Workspace App for Linux has
been installed with App Protection.

This vulnerability only affects Citrix Workspace app for Linux 2012 -
2111 and only exists if App Protection was installed as part of Citrix
Workspace app for Linux. This vulnerability does not exist if App
Protection is not installed.

Citrix Workspace app for other platforms is not affected by this issue.



What Customers Should Do
This issue has been addressed in the following versions of Citrix
Workspace app for Linux:

Citrix Workspace App for Linux 2112 and later versions

Citrix strongly recommends that affected customers upgrade to a fixed
version as soon as possible.

The latest version of Citrix Workspace app for Linux is available from
the following Citrix website location:

https://www.citrix.com/downloads/workspace-app/linux/

Acknowledgements
Citrix thanks Florian Kerber of Siemens CERT for working with us to
protect Citrix customers.
What Citrix is Doing
Citrix is notifying customers and channel partners about this potential
security issue. This article is also available from the Citrix Knowledge
Center at https://support.citrix.com/.
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact
Citrix Technical Support. Contact details for Citrix Technical Support
are available at https://www.citrix.com/support/open-a-support-case/.
Reporting Security Vulnerabilities to Citrix
Citrix welcomes input regarding the security of its products and
considers any and all potential vulnerabilities seriously. For details
on our vulnerability response process and guidance on how to report
security-related issues to Citrix, please see the following webpage:
https://www.citrix.com/about/trust-center/vulnerability-process.html.
Disclaimer
This document is provided on an "as is" basis and does not imply any
kind of guarantee or warranty, including the warranties of
merchantability or fitness for a particular use. Your use of the
information on the document is at your own risk. Citrix reserves the
right to change or update this document at any time.
Changelog
Date	Change
2022-01-11	Initial Publication



=========================================================
+ CERT-RENATER      |    tel : 01-53-94-20-44           +
+ 23/25 Rue Daviel  |    fax : 01-53-94-20-41           +
+ 75013 Paris       |    email:cert@support.renater.fr  +
=========================================================


