Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2025/VULN384

_____________________________________________________________________

DATE                : 20/06/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Citrix Workspace app for Windows
versions prior to 2409, 2402 LTSR CU2 Hotfix 1, 2402 LTSR CU3 Hotfix 1.

=====================================================================
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694718&articleURL=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2025_4879
_____________________________________________________________________

Citrix Workspace app for Windows Security Bulletin CVE-2025-4879
Article Id : CTX694718
Last Modified Date : 06-17-2025 16:02
Created Date : 06-17-2025 11:57
Article Record Type : Security Bulletin

Summary

Severity - High

Description of Problem

A vulnerability has been discovered that impacts the Citrix Workspace
app for Windows.


Affected Versions

The vulnerability affects the following supported versions of the
Citrix Workspace app for Windows

Current Release (CR)

    Citrix Workspace app for Windows versions before 2409

Long Term Service Release (LTSR)

    Citrix Workspace app for Windows versions before 2402 LTSR CU2 Hotfix 1
    Citrix Workspace app for Windows versions before 2402 LTSR CU3 Hotfix 1


Details

Citrix Workspace app for Windows contains the vulnerability
mentioned below:

CVE-ID     Description    Pre-conditions    CWE    CVSS

CVE-2025-4879
Local Privilege escalation allows a low-privileged user to gain
SYSTEM privileges 
Local access to the target system and App Protection service
should  be running
CWE-269: Improper Privilege Management
CVSS v4.0 Base Score: 7.3
(CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)


What Customers Should Do

Citrix strongly recommends that customers upgrade their Citrix
Workspace app for Windows to versions that contain the fixes as
soon as possible.  

Citrix Workspace app for Windows versions that contain the fixes
are: 

Current Release (CR)

    Citrix Workspace app for Windows 2409 and later versions 

Long Term Service Release (LTSR)

    Citrix Workspace app for Windows 2402 LTSR CU2 Hotfix 1 and later versions
    Citrix Workspace app for Windows 2402 LTSR CU3 Hotfix 1 and later versions

 
Additional information / Reference

Changelog

2025-06-17 	Initial Publication


Disclaimer

The information on this page is being provided to you on an "AS IS"
and "AS-AVAILABLE" basis. The issues described on this page may or
may not impact your system(s). Cloud Software Group, Inc. and its
subsidiaries (collectively, "Cloud SG") make no representations,
warranties, or guarantees as to the information contained herein.
ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF
MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR
PURPOSE ARE HEREBY DISCLAIMED. BY ACCESSING THIS PAGE, YOU
ACKNOWLEDGE THAT CLOUD SG SHALL IN NO EVENT BE LIABLE FOR ANY
DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES
THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION
CONTAINED HEREIN. Cloud SG reserves the right to change or update
the information on this page at any time. We accordingly recommend
that you always view the latest version of this page. The
information contained herein is being provided to you under the
terms of your applicable customer agreement with Cloud SG, and
may be used only for the purposes contemplated by such agreement.
If you do not have such an agreement with Cloud SG, this
information is provided under the cloud.com Terms of Use, and
may be used only for the purposes contemplated by such Terms
of Use.

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
