Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
History

Wed, 13 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Citrix Session Recording
Citrix Session Recording citrix Session Recording
Weaknesses CWE-94
CPEs cpe:2.3:a:citrix_session_recording:citrix_session_recording:*:*:*:*:*:*:*:*
Vendors & Products Citrix Session Recording
Citrix Session Recording citrix Session Recording
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Description Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
Title Limited remote code execution with privilege of a NetworkService Account access
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published: 2024-11-12T18:01:15.375Z

Updated: 2024-11-13T15:37:58.821Z

Reserved: 2024-08-21T23:22:40.773Z

Link: CVE-2024-8069

cve-icon Vulnrichment

Updated: 2024-11-13T15:33:45.562Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T18:15:47.603

Modified: 2024-11-13T17:01:16.850

Link: CVE-2024-8069

cve-icon Redhat

No data.