Impact
The vulnerability is an out‑of‑bounds memory read in Citrix Secure Access Client for Windows. Because the client attempts to read data beyond the intended buffer, an attacker who can trigger the flaw may access sensitive information stored nearby in memory, leading to accidental disclosure of potentially confidential data. The weakness corresponds to CWE‑125, which reflects a non‑code‑execution read flaw that can compromise confidentiality but does not result in arbitrary code execution or denial of service. The impact is limited to data leakage rather than system compromise.
Affected Systems
Citrix Secure Access Client for Windows, versions prior to 26.6.1.20, is the affected product for Citrix. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS base score of 6.8 places the flaw in the medium to high risk range, indicating that while the vulnerability can be leveraged, it does not automatically grant privileged access. The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is not explicitly documented in the available data; based on the nature of the client software and the type of flaw, it is inferred that a local or privileged user could potentially exploit the read if they can influence the client’s memory usage, or a remote attacker may succeed by sending specially crafted input if the client processes network data without proper bounds checking.
OpenCVE Enrichment