Skip to main content

Session Recording vulnerabilities

2 published alerts for Citrix Session Recording.

Actively exploited (KEV)

CVE-2024-8069

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8069). Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2024-8068

Citrix Session Recording Improper Privilege Management Vulnerability

Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8068). Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.