Impact
An out‑of‑bounds write flaw exists in Citrix Workspace app for Windows. The vulnerability permits a malicious actor to write data beyond the intended buffer limits, which can corrupt adjacent memory. According to the CVE description, this leads to unpredictable behavior such as application crashes or loss of stability. No explicit mention of privilege escalation, data exfiltration, or denial of service to other services is provided, so the impact is limited to the affected application itself.
Affected Systems
Citrix Workspace app for Windows versions before 2603.11 (Current Release), before 2507.1 LTSR CU3, and before LTSR 2607 are affected.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity. The EPSS score of less than 1 % and the lack of a listing in the CISA KEV catalog suggest a low likelihood of active exploitation. An attack vector is not explicitly documented; it can be inferred that the flaw might be triggered by a user or attacker supplying crafted data within the Workspace app or manipulating a session over a remote connection, but no confirmed public exploits are known.
OpenCVE Enrichment