C
月内に
Citrix Workspace app for Windowsに、メモリの域外読み取りおよび書き込みが可能な2件の脆弱性(CVE-2026-78546…
📌 一言でいうと
Citrix Workspace app for Windowsに、メモリの域外読み取りおよび書き込みが可能な2件の脆弱性(CVE-2026-78546、CVE-2026-78547)が公開されました。重要度は「中(Medium)」とされており、書き込みの脆弱性を悪用するには対象システムへの物理的なアクセスが必要です。Cloud Software Groupは修正済みのバージョンを公開しており、速やかなアップデートを推奨しています。
🔍該当判定
- Windows PCに「Citrix Workspace app」をインストールして利用している
- 社外から社内システムへアクセスするためにCitrixのクライアントソフトを使用している
- 利用中の「Citrix Workspace app for Windows」のバージョンが 2603.11 / 2607 LTSR / 2507.1 LTSR CU3 より古い
上記いずれにも該当しない → 静観でOK
✅該当時の対応
修正済みバージョン(2603.11、2607 LTSR、2507.1 LTSR CU3 以降)へのアップデートを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Citrix Workspace app for Windows (CVE-2026-78546, CVE-2026-78547) 対応について
お疲れさまです。Citrix Workspace app for Windowsの脆弱性に関する情報共有です。
■ 概要
メモリの域外読み取り(CVE-2026-78546)および域外書き込み(CVE-2026-78547)が可能な脆弱性が報告されました。CVSSv4.0スコアはそれぞれ4.8および4.4で、重要度は「中(Medium)」です。なお、書き込みの脆弱性については物理的なアクセスが必要とされています。
■ 影響範囲
- Citrix Workspace app for Windows
■ 対応手順
1. 利用中のバージョンを確認し、以下の修正済みバージョン以降へアップデートしてください。
- 2603.11
- 2607 LTSR
- 2507.1 LTSR CU3
■ 参考情報
- CITRIX:Citrix Workspace app for Windows Security Bulletin
対応優先度: 中
対応期限: 速やかに
お疲れさまです。Citrix Workspace app for Windowsの脆弱性に関する情報共有です。
■ 概要
メモリの域外読み取り(CVE-2026-78546)および域外書き込み(CVE-2026-78547)が可能な脆弱性が報告されました。CVSSv4.0スコアはそれぞれ4.8および4.4で、重要度は「中(Medium)」です。なお、書き込みの脆弱性については物理的なアクセスが必要とされています。
■ 影響範囲
- Citrix Workspace app for Windows
■ 対応手順
1. 利用中のバージョンを確認し、以下の修正済みバージョン以降へアップデートしてください。
- 2603.11
- 2607 LTSR
- 2507.1 LTSR CU3
■ 参考情報
- CITRIX:Citrix Workspace app for Windows Security Bulletin
対応優先度: 中
対応期限: 速やかに
Subject: [Security Advisory] Citrix Workspace app for Windows (CVE-2026-78546, CVE-2026-78547)
Dear team,
We are sharing information regarding vulnerabilities identified in Citrix Workspace app for Windows.
■ Overview
Two vulnerabilities have been disclosed: CVE-2026-78546 (out-of-bounds memory read) and CVE-2026-78547 (out-of-bounds memory write). Both are rated as 'Medium' severity, with CVSSv4.0 scores of 4.8 and 4.4, respectively. Note that the write vulnerability requires physical access to the system.
■ Affected Scope
- Citrix Workspace app for Windows
■ Remediation Steps
1. Verify the current version and update to one of the following patched versions or later:
- 2603.11
- 2607 LTSR
- 2507.1 LTSR CU3
■ Reference
- CITRIX: Citrix Workspace app for Windows Security Bulletin
Priority: Medium
Deadline: As soon as possible
Dear team,
We are sharing information regarding vulnerabilities identified in Citrix Workspace app for Windows.
■ Overview
Two vulnerabilities have been disclosed: CVE-2026-78546 (out-of-bounds memory read) and CVE-2026-78547 (out-of-bounds memory write). Both are rated as 'Medium' severity, with CVSSv4.0 scores of 4.8 and 4.4, respectively. Note that the write vulnerability requires physical access to the system.
■ Affected Scope
- Citrix Workspace app for Windows
■ Remediation Steps
1. Verify the current version and update to one of the following patched versions or later:
- 2603.11
- 2607 LTSR
- 2507.1 LTSR CU3
■ Reference
- CITRIX: Citrix Workspace app for Windows Security Bulletin
Priority: Medium
Deadline: As soon as possible