Vulnerability record · CVE-2024-8069 · published 12 November 2024
CVE-2024-8069: Citrix Session Recording deserialization allows limited RCE
Citrix · Session Recording
Citrix Session Recording is affected by deserialization of untrusted data (CWE-502), allowing limited remote code execution with the privileges of a NetworkService Account. The attacker must already be an authenticated user on the same intranet as the session recording server, which constrains who can reach and trigger the flaw.
Description
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw is in CISA KEV with known exploitation and a high EPSS percentile, but impact is limited to NetworkService privileges and requires an authenticated adjacent-network attacker.
What it is
Citrix Session Recording is affected by deserialization of untrusted data (CWE-502), allowing limited remote code execution with the privileges of a NetworkService Account. The attacker must already be an authenticated user on the same intranet as the session recording server, which constrains who can reach and trigger the flaw.
Impact
An authenticated attacker on the adjacent network can execute code with NetworkService Account privileges, giving a foothold on the session recording server rather than full administrative control.
Attack surface
Reached over the adjacent network (AV:A) by an authenticated user (PR:L) with no user interaction (UI:N), per the CVSS 4.0 vector. No public detail in the record identifies the specific endpoint or component involved.
Exploitation
CVE-2024-8069 is listed in CISA KEV (added 2025-08-25, due 2025-09-15), indicating known exploitation in the wild; EPSS 30-day probability is 0.14643 (96th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the vendor fix from the Citrix Session Recording security bulletin CTX691941 for CVE-2024-8068 and CVE-2024-8069.
- If patching is not immediately possible, follow the vendor's published mitigations or discontinue use of the product, per CISA BOD 22-01 guidance.
- Restrict intranet access to the Session Recording server so only trusted, authenticated users on the same network segment can reach it.
- Review and reduce the privileges granted to authenticated intranet accounts that can reach the Session Recording service.
Detection
- Monitor Session Recording server logs and host telemetry for unexpected child processes spawned by the NetworkService account.
- Alert on anomalous network connections to the Session Recording server from intranet hosts outside expected administrative or recording workflows.
- Hunt for deserialization-related activity or unusual object handling in Session Recording application logs around the time of suspected access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-8069 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Citrix Session Recording Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-8069 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.