Citrix Workspace app for Mac Security Bulletin for CVE-2024-7549

Citrix Workspace app for Mac Security Bulletin for CVE-2024-7549

Description of Problem

A vulnerability has been discovered in Citrix Workspace app for Mac, which, if exploited, may result in a session hijack of a user who is authenticated on cloud stores.

Affected Versions: 

The following supported versions of Citrix Workspace app for Mac are affected by the vulnerability: 
Citrix Workspace app for Mac before 2409


Summary: 

CVE ID    DescriptionPre-requisites    CWECVSS
CVE-2024-7549Possible  session hijack of a  user who is authenticated on cloud storeCitrix Workspace app authenticated user using cloud store may be impacted when:Accessing SaaS/Web appOR Accessing CVAD apps or desktops using Custom Workspace URLCWE-287: Improper AuthenticationCVSS v4.0 Base Score: 6.9(CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N) 

What Customers Should Do

Cloud Software Group strongly urges affected customers of Citrix Workspace app for Mac to install the relevant updated versions of Citrix Workspace app for Mac as soon as possible: 

  • Citrix Workspace app for Mac 2409 and later

Track the CVE on the original Citrix article: https://support.citrix.com/s/article/CTX691484-citrix-workspace-app-for-mac-security-bulletin-for-cve20247549

Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

Title

Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

CTX Number

CTX691485

Article Type

Security Bulletin

Created Date

10/Sep/2024

Last Modified Date

10/Sep/2024

Severity

High

Solution

Description of Problem

Two vulnerabilities have been discovered that impact the Citrix Workspace app for Windows.

Affected Versions

The vulnerabilities affect the following supported versions of the Citrix Workspace app for Windows.

Current Release (CR)

  • Citrix Workspace app for Windows versions BEFORE 2405

Long Term Service Release (LTSR)

  • Citrix Workspace app for Windows versions BEFORE 2402 LTSR CU1

Summary

CVE-ID Description Pre-conditionsCWECVSS
CVE-2024-7889 Local privilege escalation allows a low-privileged user to gain SYSTEM privileges Local access to the target system CWE-664: Improper Control of a Resource Through its LifetimeCVSS v4.0 Base Score: 7.0CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2024-7890Local privilege escalation allows a low-privileged user to gain SYSTEM privileges Local access to the target systemCWE-269: Improper Privilege ManagementCVSS v4.0 Base Score: 5.4CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 

What Customers Should Do

Citrix strongly recommends that customers upgrade their Citrix Workspace app for Windows to versions that contain the fixes as soon as possible.  

Citrix Workspace app for Windows versions that contain the fixes are: 

Current Release (CR)

  • Citrix Workspace app for Windows 2405 and later versions 

Long Term Service Release (LTSR)

Citrix Workspace app for Windows 2402 CU1 LTSR and later versions 

Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

CTX678035

Windows Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2024-6151

Security Bulletin | Severity: High | Created: 09 Jul 2024 | Modified: 09 Jul 2024 | Status: Final

Applicable Products

  • Citrix Virtual Apps and Desktops

Description of Problem

A vulnerability has been identified that impacts Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS. Refer to below for further details: 

Affected Versions

The vulnerability affects the following supported versions of Windows Virtual Delivery Agent: 

Current Release (CR)

  • Citrix Virtual Apps and Desktops versions before 2402 

Long Term Service Release (LTSR)

  • Citrix Virtual Apps and Desktops 1912 LTSR before CU9
  • Citrix Virtual Apps and Desktops 2203 LTSR before CU5 

Summary

Windows Virtual Delivery Agent contains the vulnerability mentioned below 

CVE ID          DescriptionPre-requisites    CWECVSS
CVE-2024-6151Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesLocal access to the target systemCWE-269: Improper Privilege ManagementCVSS v4.0 Base Score: 8.5(CVS:4.0/AV:L/AV:L/AT:N/PR:L/UI:N/VCH/VI:H/VA:H/SC:N/S:N/S:N) 

What Customers Should Do

Citrix strongly recommends that customers upgrade their Windows Virtual Delivery Agent to versions that contain the fixes as soon as possible.  

Windows Virtual Delivery Agent versions that contain the fixes are: 

Current Release (CR)

  • Citrix Virtual Apps and Desktops 2402 and later versions 

Long Term Service Release (LTSR)

  • Citrix Virtual Apps and Desktops 1912 LTSR CU9 and later cumulative updates
  • Citrix Virtual Apps and Desktops 2203 LTSR CU5 and later cumulative updates
  • Citrix Virtual Apps and Desktops 2402 LTSR
Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

CTX678025

Citrix Provisioning Security Bulletin CVE-2024-6150

Security Bulletin | Severity: Medium | Created: 09 Jul 2024 | Modified: 09 Jul 2024 | Status: Final

Applicable Products

  • Provisioning Services

Description of Problem

A vulnerability has been discovered that impacts Citrix Provisioning. Refer to below for further details: 

Affected Versions

The vulnerability affects the following supported versions of Citrix Provisioning

Current Release (CR)

  • Citrix Provisioning versions before 2402 

Long Term Service Release (LTSR)

  • Citrix Provisioning versions before 2203 LTSR CU5
  • Citrix Provisioning versions before 1912 LTSR CU9

Summary

Citrix Provisioning contains the vulnerability mentioned below 

CVE ID          DescriptionPre-requisites    CWECVSS
CVE-2024-6150A non-admin user can cause short-term disruption in Target VM availabilityAn attacker must have access to the PVSboot.ini fileCWE-284: Improper Access ControlCVSS v4.0 Base Score: 4.8(CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N) 

What Customers Should Do

Citrix strongly recommends that customers upgrade their Citrix Provisioning to versions that contain the fixes as soon as possible.  

Citrix Provisioning versions that contain the fixes are: 

Current Release (CR)

  • Citrix Provisioning 2402 and later versions 

Long Term Service Release (LTSR)

  • Citrix Provisioning 2203 LTSR CU5 and later versions
  • Citrix Provisioning 1912 LTSR CU9 and later versions
Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

CTX677100

XenServer and Citrix Hypervisor Security Update for CVE-2024-5661

Security Bulletin | Severity: Medium | Created: 11 Jun 2024 | Modified: 11 Jun 2024 | Status: Final

Applicable Products

  • Citrix Hypervisor

Description of Problem

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
This issue has the following identifier:

  • CVE-2024-5661

CVE-2024-5661 affects all deployments.

Summary

CVE IDDescriptionPre-requisitesCWECVSS
CVE-2024-5661Potential Denial of ServicePrivileged access within a guest VMCWE-7995,9

What Customers Should Do

For customers using XenServer 8, we have pushed an update to both the Early Access and Normal update channels. We recommend that customers update to the latest version from their chosen channel following the instructions at https://docs.xenserver.com/en-us/xenserver/8/update

For customers using Citrix Hypervisor 8.2 CU1 LTSR, we have released a hotfix to address this issue. We recommend that customers install this hotfix and follow the instructions in the linked article as their update schedule permits. The hotfix can be downloaded from the following location:

CTX677067- https://support.citrix.com/article/CTX677067


What Citrix is Doing

Citrix is notifying customers and channel partners about this potential security issue through the publication of this security bulletin on the Citrix Knowledge Center at https://support.citrix.com/securitybulletins.


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.

Citrix Workspace app for Windows Security Bulletin CVE-2024-7889 and CVE-2024-7890

ShareFile StorageZones Controller Security Update for CVE-2023-24489

Description of Problem

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

This vulnerability affects all currently supported versions of customer-managed ShareFile storage zones controller before version 5.11.24.

This bulletin only applies to customer-managed ShareFile storage zones controllers. Customers using ShareFile-managed storage zones in the cloud do not need to take any action.

The issue has been given the following identifier: 

CVE IDAffected ProductsDescriptionPre-requisitesCWECVSS
CVE-2023-24489Citrix Content CollaborationImproper resource control allows unauthenticated remote compromiseNetwork access to the ShareFile storage zones controllerCWE-2849.1

What Customers Should Do

This issue has been addressed in the following versions of the customer-managed ShareFile storage zones controller:

  • ShareFile storage zones controller 5.11.24 and later versions

Customers are required to upgrade to the fixed version.  

The latest version of ShareFile storage zones controller is available from the following location:

https://www.citrix.com/downloads/sharefile/product-software/sharefile-storagezones-controller-511.html

Instructions for upgrading the Storage Zones Controller are here:

https://docs.sharefile.com/en-us/storage-zones-controller/5-0/upgrade.html

All customer-managed ShareFile storage zones controllers versions prior to the latest version 5.11.24 have been blocked to protect our customers. Customers will be able to reinstate the storage zones controller once the update to 5.11.24 is applied.

Customers should shut down any machine that was running an affected version of the storage zones controller software.