Vulnerability record · CVE-2024-8068 · published 12 November 2024
CVE-2024-8068: Citrix Session Recording privilege escalation to NetworkService
Citrix · Session Recording
Citrix Session Recording contains an improper privilege management flaw (CWE-269) that lets an authenticated attacker escalate to the NetworkService account. The attacker must be a user in the same Windows Active Directory domain as the session recording server. Successful abuse grants the privileges of a built-in service account, which matters because it can widen access on the recording host beyond the attacker's normal user rights.
Description
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw is in CISA's KEV catalog, confirming real-world exploitation, but its CVSS 4.0 base score is only 5.1 (medium) and it requires an authenticated user in the same AD domain.
What it is
Citrix Session Recording contains an improper privilege management flaw (CWE-269) that lets an authenticated attacker escalate to the NetworkService account. The attacker must be a user in the same Windows Active Directory domain as the session recording server. Successful abuse grants the privileges of a built-in service account, which matters because it can widen access on the recording host beyond the attacker's normal user rights.
Impact
An attacker gains NetworkService account access on the affected Citrix Session Recording component, allowing actions and resource access available to that service identity rather than the attacker's own user account. The CVSS 4.0 vector rates confidentiality, integrity and availability impact as low.
Attack surface
The flaw is reachable over an adjacent network path (AV:A) by an authenticated user (PR:L) with no user interaction (UI:N), per the CVSS 4.0 vector. The description requires the attacker to hold a valid account in the same Windows Active Directory domain as the session recording server domain.
Exploitation
CVE-2024-8068 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2025-08-25), indicating observed exploitation, though no ransomware campaign use is recorded. EPSS gives a 30-day exploitation probability of about 1.4 percent (71st percentile), and the only references are the vendor advisory and the CISA KEV entry.
What to do
- Apply the Citrix Session Recording security update referenced in vendor bulletin CTX691941 for CVE-2024-8068 and CVE-2024-8069, or discontinue use if no fix is available.
- Follow CISA BOD 22-01 required actions and meet the KEV remediation due date of 2025-09-15.
- Restrict which Active Directory accounts can reach the Session Recording server, since exploitation requires an authenticated domain user.
- Review and reduce the privileges granted to the Session Recording service and its NetworkService context where possible.
- Monitor for unexpected use of the NetworkService identity on session recording hosts.
Detection
- Audit Citrix Session Recording server logs for privilege or identity changes involving NetworkService outside normal service startup.
- Alert on authentication and access events from domain users to the Session Recording server that precede service-account activity.
- Baseline and monitor processes or file access running as NetworkService on session recording hosts for anomalies.
- Track KEV status and vendor advisory CTX691941 for updated indicators or patch guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-8068 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Citrix Session Recording Improper Privilege Management Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-8068 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8068), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.