Skip to content
COOEY

EXPOSURES › CVE-2024-8068

CVE-2024-8068

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-8068 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Citrix Session Recording exposed to unauthorized privilege escalation due to improper access controls.

Citrix's Session Recording product suffered a high-severity vulnerability that allowed an authenticated user within the same domain to escalate privileges to the NetworkService account, posing a significant security risk to DIB organizations.

Shame score — Critical unpatched vulnerability enabling domain-level privilege escalation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Citrix for Government
Citrix
Authorized