← Vulnerability feed

Vulnerability record · CVE-2024-8068 · published 12 November 2024

CVE-2024-8068: Citrix Session Recording privilege escalation to NetworkService

Citrix · Session Recording

Citrix Session Recording contains an improper privilege management flaw (CWE-269) that lets an authenticated attacker escalate to the NetworkService account. The attacker must be a user in the same Windows Active Directory domain as the session recording server. Successful abuse grants the privileges of a built-in service account, which matters because it can widen access on the recording host beyond the attacker's normal user rights.

5.1 CVSS 4.0 Medium CISA KEV since 25 Aug 2025 EPSS 3.5% · top 11.3% CWE-269 · Improper privilege management
5.1CVSS 4.0 base score
3.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA's KEV catalog, confirming real-world exploitation, but its CVSS 4.0 base score is only 5.1 (medium) and it requires an authenticated user in the same AD domain.

What it is

Citrix Session Recording contains an improper privilege management flaw (CWE-269) that lets an authenticated attacker escalate to the NetworkService account. The attacker must be a user in the same Windows Active Directory domain as the session recording server. Successful abuse grants the privileges of a built-in service account, which matters because it can widen access on the recording host beyond the attacker's normal user rights.

Impact

An attacker gains NetworkService account access on the affected Citrix Session Recording component, allowing actions and resource access available to that service identity rather than the attacker's own user account. The CVSS 4.0 vector rates confidentiality, integrity and availability impact as low.

Attack surface

The flaw is reachable over an adjacent network path (AV:A) by an authenticated user (PR:L) with no user interaction (UI:N), per the CVSS 4.0 vector. The description requires the attacker to hold a valid account in the same Windows Active Directory domain as the session recording server domain.

Exploitation

CVE-2024-8068 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2025-08-25), indicating observed exploitation, though no ransomware campaign use is recorded. EPSS gives a 30-day exploitation probability of about 1.4 percent (71st percentile), and the only references are the vendor advisory and the CISA KEV entry.

What to do

  • Apply the Citrix Session Recording security update referenced in vendor bulletin CTX691941 for CVE-2024-8068 and CVE-2024-8069, or discontinue use if no fix is available.
  • Follow CISA BOD 22-01 required actions and meet the KEV remediation due date of 2025-09-15.
  • Restrict which Active Directory accounts can reach the Session Recording server, since exploitation requires an authenticated domain user.
  • Review and reduce the privileges granted to the Session Recording service and its NetworkService context where possible.
  • Monitor for unexpected use of the NetworkService identity on session recording hosts.

Detection

  • Audit Citrix Session Recording server logs for privilege or identity changes involving NetworkService outside normal service startup.
  • Alert on authentication and access events from domain users to the Session Recording server that precede service-account activity.
  • Baseline and monitor processes or file access running as NetworkService on session recording hosts for anomalies.
  • Track KEV status and vendor advisory CTX691941 for updated indicators or patch guidance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-8068 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Citrix Session Recording Improper Privilege Management Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8068 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.1CVE-2024-8069Citrix Session Recording deserialization allows limited RCECitrix Session Recording is affected by deserialization of untrusted data (CWE-502), allowing limited remote code execution with the privileges of a …KEVEPSS 15%analysed9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed7.8CVE-2026-21533Windows Remote Desktop improper privilege management allows local elevationWindows Remote Desktop contains an improper privilege management flaw (CWE-269) that lets an authorized attacker elevate privileges locally. It affec…KEVEPSS 4.1%analysed9.8CVE-2024-49035Microsoft Partner Center improper access control allows privilege elevationPartner.Microsoft.com contains an improper access control flaw (CWE-269) that lets an unauthenticated attacker elevate privileges over the network. M…KEVEPSS 1.3%analysed8.8CVE-2013-0643Adobe Flash Player Firefox sandbox privilege escalationAdobe Flash Player's Firefox sandbox does not properly restrict privileges, allowing crafted SWF content to escape the sandbox and run code with high…KEVEPSS 11%analysed7.8CVE-2024-38014Windows Installer Elevation of Privilege FlawCVE-2024-38014 is an elevation of privilege vulnerability in the Windows Installer, classified as improper privilege management (CWE-269). It affects…KEVEPSS 6.3%analysed7.8CVE-2024-26169Windows Error Reporting Service privilege escalation flawCVE-2024-26169 is an improper privilege management vulnerability in the Windows Error Reporting Service, classified under CWE-269. A local attacker w…KEVEPSS 4.0%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.