Impact
Citrix Workspace app for Windows contains an out‑of‑bounds read flaw that allows an attacker to read memory located outside the intended buffer. This reading can expose content of the buffer or adjacent memory used by the application, potentially revealing confidential data. The flaw does not let an attacker execute code or alter the program state; it purely allows the disclosure of memory contents.
Affected Systems
Citrix Workspace app for Windows versions older than 2603.11 Current Release, older than 2507.1 LTSR CU3, and older than LTSR 2607 are affected by this issue.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest that widespread exploitation is unlikely at this time. The likely attack vector is local; remote exploitation would require additional conditions that are not documented. The primary risk is accidental leakage of sensitive information if the application runs with elevated privileges or handles privileged data.
OpenCVE Enrichment