CVE-2024-8068: Citrix Session Recording Improper Privilege Management Vulnerability
High severity, CVSS 8.0. Actively exploited: in CISA KEV since 2025-08-25. EPSS: 3.5% chance of exploitation in the next 30 days.
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Affected products
- Citrix Session Recording: before 2407 (fixed in 2407); version 1912 only; version 2203 only; version 2402 only; version 2407 only
Published 2024-11-12. Last modified 2026-06-17.