Citrix has published security bulletins for Citrix Secure Access Client for Mac, NetScaler Console and NetScaler Agent
Samana Group LLC
Samana Group provides virtual workspaces, and services for virtual environments.
Citrix has updated security bulletins for CVE-2025-1222, CVE-2025-1223, and CVE-2024-12284:
CVE-2025-1222: A protection mechanism failure in Citrix Secure Access Client for Mac would allow an attacker with local access to the target system to gain application privileges in order to perform limited modification and/or read arbitrary data.
CVE-2025-1223: An uncontrolled search path element in Citrix Secure Access Client for Mac would allow an attacker with local access to the target system to gain application privileges in order to perform limited modification and/or read arbitrary data.
CVE-2024-12284: Improper privilege management in NetScaler Console and NetScaler Agent would allow an attacker to gain authenticated privilege escalation from the NetScaler Console Agent. This bulletin applies only to customer-managed NetScaler Console and those who have deployed NetScaler Console Agents. Customers using the Citrix-managed NetScaler Console service do not need to take any action.
We recommend that that you review the Citrix Security Bulletins to determine whether your devices are vulnerable and follow the recommendations.