HIGH
CVE-2024-8069
CVSS
8
KEV
Description
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
Summary dbcve.org
Citrix Session Recording contains a vulnerability allowing an authenticated attacker on the same intranet as the session recording server to achieve limited remote code execution with NetworkService account privileges. The requirement for both authentication and intranet access limits the exploitability, though RCE at any privilege level is a serious security concern.
Mitigation
Apply the official Citrix patch for CVE-2024-8069 when available, and enforce strict network segmentation to limit intranet access to trusted users only.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
14.64%
Probability of exploitation in next 30 days
96.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.