Skip to content
COOEY

FAIL › dossier

Session Recording

PRODUCT

· dossier confidence 80%

Session Recording is a Citrix product with a critical security posture, evidenced by two high-severity RCE vulnerabilities exploited in the wild in August 2025. The failures stem from untrusted data deserialization and improper access controls, indicating systemic issues in input validation and privilege management.

PROFILE
Categorysession recordingWhat they doSession Recording is a Citrix product that records and manages user sessions.
SECURITY POSTURE

The product has a poor security track record, with two high-severity remote code execution (RCE) vulnerabilities exploited in the wild within a single week in August 2025, stemming from untrusted data deserialization and improper access controls.

Notable failures
  • CVE-2024-8069: RCE via untrusted data deserialization
  • CVE-2024-8068: Unauthorized privilege escalation via improper access controls
Patterns: unpatched edge-device RCEs; untrusted data deserialization leading to RCE
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-08-25 CVE-2024-8069 high Citrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet
2025-08-25 CVE-2024-8068 high Citrix Session Recording exposed to unauthorized privilege escalation due to improper access controls.
Open questions: What is the current patch status for CVE-2024-8069 and CVE-2024-8068? · Are there any ongoing security audits or remediation efforts for Session Recording?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-14 03:54:08.227570+00:00