CVE-2024-8068

Confirmed PUBLISHED

Privilege escalation to NetworkService Account access

Citrix · Citrix Session Recording

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
5.1 Medium EPSS 1.4%

At a Glance

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

cisa windows
CVE Published
Nov 12, 2024
Exploitation Reported
Jun 01, 2026
CVSS
5.1 Medium
EPSS
1.4%
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Citrix
Citrix Session Recording

2407 Current Release to < 24.5.200.8

Affected
Citrix
Citrix Session Recording

1912 LTSR to < CU9 hotfix 19.12.9100.6

Affected
Citrix
Citrix Session Recording

2203 LTSR to < CU5 hotfix 22.03.5100.11

Affected
Citrix
Citrix Session Recording

2402 LTSR to < CU1 hotfix 24.02.1200.16

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.