CVE-2024-8068
Severity CVSS v4.0:
MEDIUM
Type:
CWE-269
Improper Privilege Management
Publication date:
12/11/2024
Last modified:
24/10/2025
Description
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
8.00
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:* | 2407 (excluding) | |
| cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:* | ||
| cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



