Impact
Citrix WorkSpace App for macOS contains an external control of file name or path vulnerability that can be leveraged to read or write arbitrary files on the system. This flaw enables an attacker to supply a crafted file path that may bypass normal access controls, potentially exposing sensitive data or modifying critical files.
Affected Systems
The vulnerability affects Citrix WorkSpace App version 2607 running on macOS. Systems using this version are exposed to the risk of arbitrary file access if an attacker can influence the file path parameter.
Risk and Exploitability
The CVSS score of 5.2 classifies this as a medium severity issue. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalogue, indicating no currently documented exploitation. The likely attack vector requires the attacker to influence input that controls the file path, suggesting that exploitation would need user interaction or privileged access to the application. While not highly likely, the medium impact warrants monitoring and patching if an update is available.
OpenCVE Enrichment