CVE-2024-8069: Citrix Session Recording Deserialization of Untrusted Data Vulnerability
High severity, CVSS 8.0. Actively exploited: in CISA KEV since 2025-08-25. EPSS: 14.6% chance of exploitation in the next 30 days.
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
Affected products
- Citrix Session Recording: before 2407 (fixed in 2407); version 1912 only; version 2203 only; version 2402 only; version 2407 only
Published 2024-11-12. Last modified 2026-06-17.