NetScaler ADC and Gateway
CVE-2023-24491: A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited,…
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Citrix Secure Access client for Windows (Windows) 0 | 23.5.1.3 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.