Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
References
Configurations
Configuration 1 (hide)
|
History
25 Jul 2025, 17:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:citrix:session_recording:2402:-:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2407:-:*:*:-:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:cu5:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:* cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:* cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:* |
|
References | () https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
First Time |
Citrix session Recording
Citrix |
Information
Published : 2024-11-12 18:15
Updated : 2025-07-25 17:10
NVD link : CVE-2024-8068
Mitre link : CVE-2024-8068
CVE.ORG link : CVE-2024-8068
JSON object : View
Products Affected
citrix
- session_recording
CWE
CWE-269
Improper Privilege Management