Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
History

Tue, 26 Aug 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:citrix:session_recording:2203:cu5:*:*:ltsr:*:*:*
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 26 Aug 2025 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 25 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:citrix_session_recording:citrix_session_recording:*:*:*:*:*:*:*:*
Vendors & Products Citrix Session Recording
Citrix Session Recording citrix Session Recording
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

kev

{'dateAdded': '2025-08-25T00:00:00+00:00', 'dueDate': '2025-09-15T00:00:00+00:00'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix session Recording
CPEs cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu5:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2402:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2407:-:*:*:-:*:*:*
Vendors & Products Citrix
Citrix session Recording

Wed, 13 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Citrix Session Recording
Citrix Session Recording citrix Session Recording
Weaknesses CWE-94
CPEs cpe:2.3:a:citrix_session_recording:citrix_session_recording:*:*:*:*:*:*:*:*
Vendors & Products Citrix Session Recording
Citrix Session Recording citrix Session Recording
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Description Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
Title Limited remote code execution with privilege of a NetworkService Account access
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2025-08-26T03:55:20.543Z

Reserved: 2024-08-21T23:22:40.773Z

Link: CVE-2024-8069

cve-icon Vulnrichment

Updated: 2024-11-13T15:33:45.562Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T18:15:47.603

Modified: 2025-08-26T14:44:23.440

Link: CVE-2024-8069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.