Session Recording vulnerabilities
2 published alerts for Citrix Session Recording.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8069). Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.
Citrix Session Recording Improper Privilege Management Vulnerability
Citrix Session Recording is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-8068). Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain. CISA remediation due date: 2025-09-15. If you need help checking exposure, call (864) 335-9223.