CVE-2019-11634: Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 8.1% chance of exploitation in the next 30 days.

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Affected products

  • Citrix Receiver: version 4.9 only
  • Citrix Workspace: before 1904 (fixed in 1904)

Published 2019-05-22. Last modified 2026-08-12.