Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
History

Fri, 25 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Citrix
Citrix session Recording
CPEs cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:*
cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2203:cu5:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2402:-:*:*:ltsr:*:*:*
cpe:2.3:a:citrix:session_recording:2407:-:*:*:-:*:*:*
Vendors & Products Citrix
Citrix session Recording

Wed, 13 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Citrix Session Recording
Citrix Session Recording citrix Session Recording
Weaknesses CWE-94
CPEs cpe:2.3:a:citrix_session_recording:citrix_session_recording:*:*:*:*:*:*:*:*
Vendors & Products Citrix Session Recording
Citrix Session Recording citrix Session Recording
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Description Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
Title Limited remote code execution with privilege of a NetworkService Account access
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2024-11-15T04:55:51.734Z

Reserved: 2024-08-21T23:22:40.773Z

Link: CVE-2024-8069

cve-icon Vulnrichment

Updated: 2024-11-13T15:33:45.562Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T18:15:47.603

Modified: 2025-07-25T18:30:27.460

Link: CVE-2024-8069

cve-icon Redhat

No data.