November 3, 2021 · Applied Cybernetics Group
CVE-2019-11634 — Citrix Workspace Application and Receiver for Windows
known ransomware use
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Citrix
- Product
- Workspace Application and Receiver for Windows
- EPSS
- 98.0th percentile (score 0.524, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-11634
CISA short description
Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.
Required action
Apply updates per vendor instructions.