Citrix Workspace App for Windows Multiple Vulnerabilities (CTX697034)

medium Nessus Plugin ID 349718

Synopsis

The remote host is missing a security update.

Description

The version of Citrix Workspace App installed on the remote Windows host is 2507 / 2507.1 LTSR prior to 2507.1 LTSR CU3, or a Current Release prior to 2603.11. It is, therefore, affected by multiple vulnerabilities:

- An out-of-bounds read vulnerability exists in Citrix Workspace app for Windows. An attacker with local access to the target system can exploit this to disclose sensitive information. (CVE-2026-78546)

- An out-of-bounds write vulnerability exists in Citrix Workspace app for Windows. An attacker with physical access to the target system can exploit this to impact integrity and availability. (CVE-2026-78547)

Solution

Upgrade to Citrix Workspace App for Windows 2603.11 CR, 2507.1 LTSR CU3, 2607 LTSR or later.

See Also

http://www.nessus.org/u?cbea1ed3

Plugin Details

Severity: Medium

ID: 349718

File Name: citrix_workspace_CTX697034.nasl

Version: 1.1

Type: Local

Agent: windows

Family: Windows

Published: 9/24/2026

Updated: 9/24/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.23

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-78547

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4

Risk Factor: Medium

Base Score: 4.8

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:citrix:workspace

Required KB Items: installed_sw/Citrix Workspace, SMB/Registry/Enumerated

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-78546, CVE-2026-78547