EXPOSURES › CVE-2024-8069
CVE-2024-8069
HIGH ⌖ ON CISA KEV · EXPLOITEDCitrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet
Citrix's Session Recording product suffered a vulnerability that allowed unauthenticated attackers on the same intranet to execute arbitrary code with the privileges of the NetworkService account, as exploited in the wild.
Shame score — Critical remote code execution flaw exploited by unauthenticated attackers on the same network, leading to unauthorized access and potential data exfiltration.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
| PRODUCT | STATUS |
|---|---|
| Citrix for Government Citrix |
Authorized |