CVE-2022-21827 is an improper privilege vulnerability in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) versions prior to 21.9.1.2. A local attacker can leverage this to corrupt or delete files with SYSTEM privileges. Rated 7.1 HIGH, this vulnerability requires local access but has low attack complexity, potentially leading to high integrity and availability impacts. There is no public exploit code available, it is not actively exploited, and it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.9.1.2CPE matchmatch criteria | cpe:2.3:a:citrix:gateway_plug-in:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.