CVE-2024-8069

Confirmed PUBLISHED

Limited remote code execution with privilege of a NetworkService Account access

Citrix Session Recording · Citrix Session Recording

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
5.1 Medium EPSS 14.7%

At a Glance

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

cisa
CVE Published
Nov 12, 2024
Exploitation Reported
Jun 01, 2026
CVSS
5.1 Medium
EPSS
14.7%
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Citrix Session Recording
Citrix Session Recording

2407 Current Release to < 24.5.200.8

Affected
Citrix Session Recording
Citrix Session Recording

1912 LTSR to < CU9 hotfix 19.12.9100.6

Affected
Citrix Session Recording
Citrix Session Recording

2203 LTSR to < CU5 hotfix 22.03.5100.11

Affected
Citrix Session Recording
Citrix Session Recording

2402 LTSR to < CU1 hotfix 24.02.1200.16

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.