← Back to CVE List
Vulnerability Intelligence Report
Privilege escalation to NetworkService Account access

CVE-2024-8068

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

CISA KEV SSVC: Active Exploitation
CVSS Base Score
5.1
MEDIUM
EPSS Probability:1.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-269 ↗CWE-269 Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
Citrix Citrix Session Recording 2407 Current Release < 24.5.200.8 (affected), 1912 LTSR < CU9 hotfix 19.12.9100.6 (affected), 2203 LTSR < CU5 hotfix 22.03.5100.11 (affected), 2402 LTSR < CU1 hotfix 24.02.1200.16 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.399%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCitrix Systems, Inc. · Vendor · USA
Reserved2024-08-21T23:22:39
Published2024-11-12T17:49:54
Last Updated2025-10-21T22:55:37

LINK COPIED TO CLIPBOARD