ZeroHour

CVE-2024-8068

KEVlarge

Privilege Escalation to NetworkService Account in Citrix Session Recording

CISA: Citrix Session Recording Improper Privilege Management Vulnerability

CVSS 4.0
5.1 medium
EPSS
1%p71
Published
()
KEV added
AI analysis

CVE-2024-8068 is an improper privilege management flaw (CWE-269) in Citrix Session Recording that allows an attacker to escalate to NetworkService Account privileges on the Session Recording server. It is triggered by an authenticated user in the same Windows Active Directory domain as the Session Recording server, who can reach the service over an adjacent network connection (CVSS 4.0 vector AV:A, PR:L, AC:L). A successful attacker gains service-level privileges as the NetworkService account on the recording server, with low-impact effects on that system that could support further lateral movement within the domain. Only organizations running Citrix Session Recording, typically deployed as an optional component of Citrix Virtual Apps and Desktops or Citrix DaaS environments, are affected; unauthenticated or out-of-domain attackers are excluded. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-08-25, confirming exploitation in the wild (ransomware use unknown); no public proof-of-concept is known and EPSS estimates a 1.4% probability of exploitation in the next 30 days.

What to do: Upgrade Session Recording to the fixed releases listed in Citrix's security bulletin and verify the installed build on all recording servers, since the component is often deployed and forgotten. Enumerate which domain users can reach the Session Recording service and restrict access/segment it from general domain accounts to reduce exposure. Federal agencies must apply vendor mitigations or discontinue use under BOD 22-01 timelines because the flaw is KEV-listed.

Affected
Citrix Session Recording
Estimated exposure
large≈ tens of thousands of Session Recording server deployments worldwide (optional component of Citrix Virtual Apps and Desktops estates) — Session Recording is an optional add-on deployed in a subset of Citrix Virtual Apps and Desktops/Citrix DaaS environments whose large enterprise install base plausibly implies tens of thousands of recording servers, most of which are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

CISA Known Exploited Vulnerability
Affected
Citrix Session Recording
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
citrix
Products
session recording
Weakness
CWE-269
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news