Citrix provides sample scripts that can be downloaded from one of the Workspace app or Receiver download pages (Workspace app version 2103.1 (Current Release), or Workspace app version 1912 CU3 (aka ) (LTSR), Receiver version 4.9.9002 (LTSR) by expanding Downloads for Admins (Deployment Tools). Note: We currently recommend Citrix Workspace for Windows or for Mac version 1904 or later. Warning: There is an issue in Receiver for Windows in versions. Citrix has addressed this issue in version LTSR 4.9 CU6 (4.9.6001) but has NOT addressed it in 4.8, 4.10, 4.11, or 4.12. Author Marco Posted on Categories Citrix, Workspace app (receiver), XenApp 7.x Tags Citrix, Citrix Receiver, LTSR Leave a Reply Cancel reply Your email address will not be published. In order to facilitate migration from CVAD 7.15 LTSR to CVAD LTSR, Citrix has marked the use of the latest 7.15 LTSR VDA as a compatible component of CVAD 1912 LTSR site. However, if there is an issue with the 7.15 VDA, they should expect the fixes to be delivered via a 7.15 Cumulative Update VDA.
This vulnerability has been assigned the following CVE number:
• CVE-2019-11634: Remote Code Execution Vulnerability in Citrix Workspace app for Windows prior to version 1904 and Receiver for Windows to LTSR 4.9 CU6 version earlier than 4.9.6001.
This vulnerability affects all versions of Citrix Workspace app for Windows and Receiver for Windows the fix is contained in Citrix Workspace app version 1904 or later and Receiver for Windows to LTSR 4.9 CU6 version 4.9.6001.
This vulnerability does not affect Citrix Workspace app and Receiver on any other platforms. Warcraft 3 frozen throne for mac os.
Mitigating Factors
Citrix strongly recommends that customers upgrade to the latest Citrix Workspace app for Windows and Receiver for Windows to address this vulnerability. In cases where the upgrade is not immediately possible applying a Client Selective Trust policy via GPO can be used to limit the exploitability of this vulnerability until the upgrade can be completed. The following settings must be set for both x86 and x64 hives and the client system must be rebooted to take effect.
Set all FileSecurityPermission to 0, which means No Access (See CTX133565 for further details)
And
Set InstantiatedSecurityPolicyEditabledefault to false (See CTX128792 for further details)
Note: Restarting Citrix Workspace app and Receiver is not sufficient to apply the changes, the operating system must be rebooted.
What Customers Should Do
Logos. A new version of Citrix Workspace app and Receiver for Windows has been released. Citrix strongly recommends that customers upgrade Citrix Workspace app to version 1904 or later and Receiver for Windows to LTSR 4.9 CU6 version 4.9.6001.
The new Citrix Workspace app version is available from the following Citrix website location:
The new LTSR version is available from the following Citrix website location:
Citrix Workspace Lts
Single Sign-on (SSO) could stop working, after applying the security update, for browsers other than Internet Explorer unless explicitly configured. Use the following documentation to ensure proper configuration post fix installation:
Acknowledgements
Citrix thanks Ollie Whitehouse, Richard Warren and Martin Hill of NCC Group for working with us to protect Citrix customers.
What Citrix Is Doing
Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at http://support.citrix.com/.
Obtaining Support on This Issue
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://www.citrix.com/support/open-a-support-case.html.
Reporting Security Vulnerabilities
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For guidance on how to report security-related issues to Citrix, please see the following document: CTX081743 – Reporting Security Issues to Citrix Best download manager for chrome.
Changelog
Date | Change |
13th May 2019 | Initial publishing |
17th May 2019 | Clarified affected version statement |
24th May 2019 | Added 'Mitigating Factors' section |
Citrix has released Citrix Workspace app 1912 LTSR CU1 Hotfix 1 which has been published in the Liquit Setup Store and has been checked for MSIX readiness.
This update addresses a security issue described in CVE-2020-8207 which has an overall CVSS Score of 8.8 (high). For more information, see Knowledge Center article CTX277662. [CVADHELP-15613].
Citrix Workspace App 19.12.1001 Download
This blog describes how to create a Managed Package for another Setup Store title, but the steps to create one for Citrix Workspace app are the same.
Recommended reading:
The Three Components of Liquit Release & Patch Management.
Download Citrix Workspace 1912 Ltsr Cu1
Please contact our sales team to try Liquit Release & Patch Management free of charge for 30 days.