10 results (0.012 seconds)

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

07 Dec 2023 — Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline. El modo sin conexión siempre está habilitado, incluso si el permiso no lo permite, en la fuente de datos del servidor de Devolutions en Devolutions Workspace 2023.3.2.0 y versiones anteriores. Esto permite que un atacante con acceso a la aplicación Workspace acce... • https://devolutions.net/security/advisories/DEVO-2023-0022 •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

10 Jul 2023 — A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. • https://support.citrix.com/article/CTX477618/citrix-workspace-app-for-linux-security-bulletin-for-cve202324486 • CWE-284: Improper Access Control •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

24 Apr 2023 — Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business sp... • https://devolutions.net/security/advisories/DEVO-2023-0011 • CWE-863: Incorrect Authorization •

CVSS: 5.5EPSS: 0%CPEs: 11EXPL: 0

16 Feb 2023 — A malicious user can cause log files to be written to a directory that they do not have permission to write to. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control •

CVSS: 7.8EPSS: 0%CPEs: 11EXPL: 0

16 Feb 2023 — Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. • https://support.citrix.com/article/CTX477617/citrix-workspace-app-for-windows-security-bulletin-for-cve202324484-cve202324485 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

07 Feb 2023 — Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. • https://github.com/ONLYOFFICE/DocumentServer/blob/master/CHANGELOG.md#733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

09 Feb 2022 — An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. Se presenta una vulnerabilidad de control de acceso inapropiado en Citrix Workspace App for Linux 2012 - 2111 con App Protection instalado que puede permitir a un atacante llevar a cabo una escalada de privilegios local • https://support.citrix.com/article/CTX338435 • CWE-284: Improper Access Control •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

27 May 2021 — An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2105 and 1912 LTSR prior to CU4. Se presenta una vulnerabilidad de control de acceso inapropiado en la aplicación Citrix Workspace para Windows que potencialmente permite una escalada de privilegios en CR versiones anteriores a 2105 y 1912 LTSR versiones anteriores a CU4 • https://support.citrix.com/article/CTX307794 • CWE-284: Improper Access Control •

CVSS: 8.8EPSS: 1%CPEs: 2EXPL: 0

24 Jul 2020 — Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running. Un control de acceso inapropiado en la aplicación Citrix Workspace para Windows versiones 1912 CU1 y 2006.1, causa una escalada de privilegios y una ejecución del código cuando el servicio de actualización automática es ejecutado • https://support.citrix.com/article/CTX277662 • CWE-284: Improper Access Control CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 59%CPEs: 2EXPL: 0

22 May 2019 — Citrix Workspace App before 1904 for Windows has Incorrect Access Control. La aplicación Citrix Workspace antes de 1904 para Windows tiene un control de acceso incorrecto. Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. • https://support.citrix.com/article/CTX251986 • CWE-284: Improper Access Control •