Skip to content
COOEY

EXPOSURES › CVE-2019-11634

CVE-2019-11634

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11634 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems.

CVE-2019-11634 in Citrix Workspace allowed attackers to execute code due to improperly enforced local drive access, which is a significant risk for DIB organizations using Citrix solutions; this failure exposes systems to ransomware and compliance violations (NIST 800-171 controls 3.1.1, 3.1.2, 3.1.3); immediately patch vulnerable systems and review Citrix configurations.

Shame score — The vulnerability was actively exploited by ransomware groups, indicating a failure to adequately secure a widely-used product and a lack of proactive security measures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized