Description of Problem
A vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows). If exploited, this issue would allow an adversary, who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM. This issue has the following identifier:
CVE-ID | Description | CWE | Pre-conditions |
CVE-2022-21827 | Arbitrary corruption or deletion of files as SYSTEM | CWE-284: Improper Access Control | Local access to a machine that has the vulnerable plug-in installed |
The following supported versions of Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) are affected by this vulnerability:
- Citrix Gateway Plug-in for Windows versions before 21.9.1.2
What Customers Should Do
This issue has been addressed in the following versions of Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows):
- Citrix Gateway Plug-in for Windows version 21.9.1.2 and later releases
Download Link: https://www.citrix.com/downloads/citrix-gateway/plug-ins/citrix-secure-access-client-for-windows.html
The original Citrix article can be found here: https://support.citrix.com/article/CTX341455