HIGH

CVE-2024-8069

Citrix Session Recording 2024-11-12 CVSS v3.1
CVSS
8
KEV

Description

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

Summary dbcve.org

Citrix Session Recording contains a vulnerability allowing an authenticated attacker on the same intranet as the session recording server to achieve limited remote code execution with NetworkService account privileges. The requirement for both authentication and intranet access limits the exploitability, though RCE at any privilege level is a serious security concern.

Mitigation

Apply the official Citrix patch for CVE-2024-8069 when available, and enforce strict network segmentation to limit intranet access to trusted users only.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

14.64%
Probability of exploitation in next 30 days
96.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE