6
CVSSv2

CVE-2020-8207

Published: 24/07/2020 Updated: 29/07/2020
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citrix workspace 1912

citrix workspace 2002

Vendor Advisories

Description of Problem A vulnerability has been identified in the automatic update service of Citrix Workspace app for Windows that could result in: A local user escalating their privilege level to that of an administrator on the computer running Citrix Workspace app for Windows A remote compromise of t ...

Recent Articles

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace app could let remote attacker pwn host
The Register • Gareth Corfield • 21 Jul 2020

Patch out for Pen Test Partners-spotted vuln – you know what to do

Research outfit Pen Test Partners has uncovered a vulnerability in the Citrix Workspace app potentially allowing a privilege escalation to lead to full remote compromise of the host machine. The flaw, CVE-2020-8207 (not yet reserved at the time of publication), sees Workspace app's automatic update feature abused to gain access to a vulnerable Workspace app installation, with the attack vector being a named pipe. The hole has been patched and users of Citrix Workspace app should install the late...

Stick that in your named pipe and smoke it: Flaw in Citrix Workspace app could let remote attacker pwn host
The Register • Gareth Corfield • 21 Jul 2020

Patch out for Pen Test Partners-spotted vuln – you know what to do

Research outfit Pen Test Partners has uncovered a vulnerability in the Citrix Workspace app potentially allowing a privilege escalation to lead to full remote compromise of the host machine. The flaw, CVE-2020-8207 (not yet reserved at the time of publication), sees Workspace app's automatic update feature abused to gain access to a vulnerable Workspace app installation, with the attack vector being a named pipe. The hole has been patched and users of Citrix Workspace app should install the late...