🔐 CVE Alert

CVE-2024-8068

UNKNOWN 0.0 ⚠️ CISA KEV

Privilege escalation to NetworkService Account access

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

CWE CWE-269
Vendor citrix
Product citrix session recording
Ecosystems
Industries
TechnologyEnterprise
Published Nov 12, 2024
Last Updated Oct 21, 2025
⚠️ Actively Exploited — Act Now

Get instant alerts for citrix citrix session recording

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2024-8068.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Citrix / Citrix Session Recording
2407 Current Release < 24.5.200.8 1912 LTSR < CU9 hotfix 19.12.9100.6 2203 LTSR < CU5 hotfix 22.03.5100.11 2402 LTSR < CU1 hotfix 24.02.1200.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.citrix.com: https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8068