📦

workspace

Vendor: onevision

Actively Exploited 1 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.93% Exploit Prob.
Latest CVE CVE-2025-4879 Jun 17

Security Vulnerability Index

Page 1 / 1
7.3 CVSS

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

EPSS: 0.07%
4.9 CVSS

OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

EPSS: 0.23%
5.4 CVSS

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

EPSS: 0.12%
7.0 CVSS

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

EPSS: 0.13%
6.1 CVSS

Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.

EPSS: 0.03%
8.5 CVSS

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

EPSS: 0.15%
4.8 CVSS

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

EPSS: 0.43%
5.3 CVSS

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

EPSS: 0.09%
6.3 CVSS

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

EPSS: 0.14%
6.5 CVSS

Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

EPSS: 0.25%