HIGH

CVE-2024-8068

Citrix Session Recording 2024-11-12 CVSS v3.1
CVSS
8
KEV

Description

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

Summary dbcve.org

In Citrix Session Recording, an authenticated user in the same Windows Active Directory domain as the session recording server can escalate privileges to gain NetworkService Account access. This represents a vertical privilege escalation from a standard authenticated user to a higher-privileged service account context within the Windows environment.

Mitigation

Implement least-privilege access controls on AD user accounts, restrict domain user permissions to Citrix Session Recording servers, apply vendor patches when available, and consider network segmentation to limit exposure. Review ACLs and service account configurations in the meantime.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

1.4%
Probability of exploitation in next 30 days
70.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE