CVE-2012-4603: Citrix Receiver

High severity, CVSS 7.8. EPSS: 6.9% chance of exploitation in the next 30 days.

Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.

Affected products

  • Citrix Receiver: up to and including 3.2
  • Citrix Xenapp Online: up to and including 12.1

Published 2020-01-10. Last modified 2026-06-16.