← Vulnerability feed

Vulnerability record · CVE-2024-8069 · published 12 November 2024

CVE-2024-8069: Citrix Session Recording deserialization allows limited RCE

Citrix · Session Recording

Citrix Session Recording is affected by deserialization of untrusted data (CWE-502), allowing limited remote code execution with the privileges of a NetworkService Account. The attacker must already be an authenticated user on the same intranet as the session recording server, which constrains who can reach and trigger the flaw.

5.1 CVSS 4.0 Medium CISA KEV since 25 Aug 2025 EPSS 15% · top 3.5% CWE-502 · Deserialization of untrusted data
5.1CVSS 4.0 base score
15%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with known exploitation and a high EPSS percentile, but impact is limited to NetworkService privileges and requires an authenticated adjacent-network attacker.

What it is

Citrix Session Recording is affected by deserialization of untrusted data (CWE-502), allowing limited remote code execution with the privileges of a NetworkService Account. The attacker must already be an authenticated user on the same intranet as the session recording server, which constrains who can reach and trigger the flaw.

Impact

An authenticated attacker on the adjacent network can execute code with NetworkService Account privileges, giving a foothold on the session recording server rather than full administrative control.

Attack surface

Reached over the adjacent network (AV:A) by an authenticated user (PR:L) with no user interaction (UI:N), per the CVSS 4.0 vector. No public detail in the record identifies the specific endpoint or component involved.

Exploitation

CVE-2024-8069 is listed in CISA KEV (added 2025-08-25, due 2025-09-15), indicating known exploitation in the wild; EPSS 30-day probability is 0.14643 (96th percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor fix from the Citrix Session Recording security bulletin CTX691941 for CVE-2024-8068 and CVE-2024-8069.
  • If patching is not immediately possible, follow the vendor's published mitigations or discontinue use of the product, per CISA BOD 22-01 guidance.
  • Restrict intranet access to the Session Recording server so only trusted, authenticated users on the same network segment can reach it.
  • Review and reduce the privileges granted to authenticated intranet accounts that can reach the Session Recording service.

Detection

  • Monitor Session Recording server logs and host telemetry for unexpected child processes spawned by the NetworkService account.
  • Alert on anomalous network connections to the Session Recording server from intranet hosts outside expected administrative or recording workflows.
  • Hunt for deserialization-related activity or unusual object handling in Session Recording application logs around the time of suspected access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-8069 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Citrix Session Recording Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.1CVE-2024-8068Citrix Session Recording privilege escalation to NetworkServiceCitrix Session Recording contains an improper privilege management flaw (CWE-269) that lets an authenticated attacker escalate to the NetworkService …KEVEPSS 3.5%analysed9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed9.3CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 PHP object injection RCEMirasvit Full Page Cache Warmer for Magento 2 before 1.11.12 passes the CacheWarmer cookie to PHP's native unserialize() without restriction, allowin…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.