EXPOSURES › CVE-2024-8068
CVE-2024-8068
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix Session Recording exposed to unauthorized privilege escalation due to improper access controls.
Citrix's Session Recording product suffered a high-severity vulnerability that allowed an authenticated user within the same domain to escalate privileges to the NetworkService account, posing a significant security risk to DIB organizations.
Shame score — Critical unpatched vulnerability enabling domain-level privilege escalation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |