CVE-2023-24491: Citrix Secure Access Client
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Affected products
- Citrix Secure Access Client: before 23.5.1.3 (fixed in 23.5.1.3)
Published 2023-07-11. Last modified 2026-06-17.