CVE-2024-8068
KEVlargePrivilege Escalation to NetworkService Account in Citrix Session Recording
CISA: Citrix Session Recording Improper Privilege Management Vulnerability
CVE-2024-8068 is an improper privilege management flaw (CWE-269) in Citrix Session Recording that allows an attacker to escalate to NetworkService Account privileges on the Session Recording server. It is triggered by an authenticated user in the same Windows Active Directory domain as the Session Recording server, who can reach the service over an adjacent network connection (CVSS 4.0 vector AV:A, PR:L, AC:L). A successful attacker gains service-level privileges as the NetworkService account on the recording server, with low-impact effects on that system that could support further lateral movement within the domain. Only organizations running Citrix Session Recording, typically deployed as an optional component of Citrix Virtual Apps and Desktops or Citrix DaaS environments, are affected; unauthenticated or out-of-domain attackers are excluded. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-08-25, confirming exploitation in the wild (ransomware use unknown); no public proof-of-concept is known and EPSS estimates a 1.4% probability of exploitation in the next 30 days.
What to do: Upgrade Session Recording to the fixed releases listed in Citrix's security bulletin and verify the installed build on all recording servers, since the component is often deployed and forgotten. Enumerate which domain users can reach the Session Recording service and restrict access/segment it from general domain accounts to reduce exposure. Federal agencies must apply vendor mitigations or discontinue use under BOD 22-01 timelines because the flaw is KEV-listed.
| Citrix Session Recording | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
- Affected
- Citrix Session Recording
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- citrix
- Products
- session recording
- Weakness
- CWE-269
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X