CVE-2024-8068

HIGH(8.0)KEV

Citrix Session Recording Improper Privilege Management Vulnerability

Description

CVE-2024-8068 is a high-severity privilege escalation vulnerability in Citrix Session Recording that allows an authenticated user in the same Windows Active Directory domain to escalate their privileges to the NetworkService account on the Session Recording server. With a CVSS v3.1 base score of 8.0, this vulnerability enables domain users with minimal privileges to execute actions under the elevated NetworkService context, potentially accessing sensitive session recordings and compromising the integrity of the recording infrastructure. CISA has added CVE-2024-8068 to the Known Exploited Vulnerabilities catalog with a remediation deadline of September 15, 2025, and its EPSS score of 8.05% at the 91st percentile indicates significant exploitation activity.

KEV Information

Vendor
Citrix
Product
Session Recording
Date Added
August 25, 2025
Due Date
September 15, 2025
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.1
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
citrixsession recording< 2407; 1912; 2203; 2402; 2407

References

Weakness Type

CWE-269: Improper Privilege Management

CVE-2024-8068 is classified under CWE-269 (Improper Privilege Management). This weakness occurs when a product does not properly assign, modify, track, or check privileges for actors. In Citrix Session Recording, the privilege management flaw allows an authenticated domain user to escalate to the NetworkService account, gaining access to functionality and data that should be restricted to higher-privileged service accounts.

Learn more: CWE-269 — Improper Privilege Management

Impact Analysis

CVE-2024-8068 presents a significant risk to organizations using Citrix Session Recording for compliance and security monitoring. The attack vector is adjacent network (AV:A), meaning the attacker must be on the same network or Active Directory domain as the Session Recording server. Attack complexity is low (AC:L), requiring only low privileges (PR:L) in the form of a standard domain user account, with no user interaction needed (UI:N). Confidentiality (High): The NetworkService account typically has access to all session recordings stored on the server, which may contain sensitive information including credentials, confidential business data, and user activity details captured during recorded sessions. Integrity (High): With NetworkService privileges, the attacker can modify or delete session recordings, potentially tampering with audit evidence or covering tracks of malicious activity. Availability (High): The attacker can disrupt the Session Recording service, preventing new sessions from being recorded and potentially destroying existing recordings. This vulnerability is particularly concerning because Session Recording is often deployed specifically for security and compliance purposes, and its compromise undermines the very controls it is meant to provide.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2024-8068 by adding it to the Known Exploited Vulnerabilities catalog with a remediation deadline of September 15, 2025. The EPSS score of 8.05% at the 91st percentile indicates substantial exploitation activity, placing it in the top 9% of vulnerabilities by exploitation probability. Citrix has published a combined security bulletin (CTX691941) addressing both CVE-2024-8068 and the related CVE-2024-8069, which involves deserialization-based remote code execution in the same product. The combination of these two vulnerabilities creates a particularly dangerous attack chain: CVE-2024-8068 provides privilege escalation, and CVE-2024-8069 enables code execution, potentially allowing a low-privileged domain user to achieve remote code execution on the Session Recording server.

Remediation

  1. Apply the Citrix security update. Install the patched version of Citrix Session Recording as specified in the Citrix security bulletin CTX691941. Ensure you address both CVE-2024-8068 and CVE-2024-8069 simultaneously since both affect the same product.

  2. Restrict network access to the Session Recording server. Implement network segmentation to limit which systems and users can communicate with the Session Recording server. Only Citrix Virtual Apps and Desktops delivery controllers and authorized administrative workstations should have network access to the recording infrastructure.

  3. Review Active Directory permissions. Audit which domain users have access to the network segment where the Session Recording server resides. Apply the principle of least privilege to minimize the number of users who could potentially exploit this vulnerability.

  4. Verify recording integrity. After patching, review existing session recordings for signs of tampering or unauthorized access. Check server logs for unusual authentication patterns or privilege escalation attempts from standard domain user accounts.

  5. Monitor for the related CVE-2024-8069. Since both vulnerabilities affect the same Citrix Session Recording product and can be chained together, ensure your patching addresses both CVEs. Implement monitoring for deserialization-related attack patterns and unusual process execution on the Session Recording server.

Technical Details

CVE-2024-8068 is a privilege escalation vulnerability in Citrix Session Recording. The CVSS v3.1 vector string CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H indicates an adjacent network attack requiring low privileges and no user interaction, with high impact across all CIA dimensions. The vulnerability exists in the privilege management logic of the Session Recording service, which fails to properly validate and restrict privilege transitions for authenticated domain users. An attacker with a standard Active Directory domain account on the same network as the Session Recording server can exploit this flaw to escalate their privileges to the NetworkService account. The NetworkService account is a built-in Windows account that runs with the machine's identity on the network, providing significant access to local resources and the ability to authenticate to other network services. In the context of Citrix Session Recording, this account has access to recorded session data, configuration files, and service management functions. The scope is unchanged (S:U), meaning the impact is contained to the Session Recording server, though the data accessible through recorded sessions may contain information about other systems and users. Affected versions include Citrix Session Recording releases 1912, 2203, 2402, and versions before 2407.

Frequently Asked Questions

Is CVE-2024-8068 being actively exploited?

Yes. CISA has confirmed active exploitation by adding CVE-2024-8068 to the Known Exploited Vulnerabilities catalog. The EPSS score of 8.05% at the 91st percentile indicates significant exploitation activity. This vulnerability is often chained with CVE-2024-8069 for greater impact.

What products are affected by CVE-2024-8068?

Citrix Session Recording versions 1912, 2203, 2402, and versions prior to 2407 are affected. The vulnerability requires the attacker to be an authenticated user in the same Windows Active Directory domain as the Session Recording server.

How do I fix CVE-2024-8068?

Apply the Citrix security update referenced in bulletin CTX691941. Also patch CVE-2024-8069 simultaneously since both affect the same product. After patching, restrict network access to the Session Recording server and review session recording integrity.

How severe is CVE-2024-8068?

CVE-2024-8068 has a CVSS v3.1 base score of 8.0 (High severity). It enables privilege escalation from a standard domain user to the NetworkService account, granting access to sensitive session recordings. When combined with CVE-2024-8069, the attack chain can achieve remote code execution.

CVSS Score

8.0
HIGH(8.0)

EPSS Score

EPSS Score1.39%
EPSS Percentile70.1%

Dates

PublishedNovember 12, 2024
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.