CVE-2024-8069: Citrix Session Recording Deserialization of Untrusted Data Vulnerability
Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.
Other sources
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8069?
CVE-2024-8069 is classified as a limited remote code execution vulnerability with impact on the NetworkService account.
How do I fix CVE-2024-8069?
To mitigate CVE-2024-8069, ensure that you apply the latest security updates provided by Citrix for Session Recording.
Who is affected by CVE-2024-8069?
CVE-2024-8069 affects authenticated users on the same intranet as the Citrix Session Recording server.
What are the implications of CVE-2024-8069?
Exploitation of CVE-2024-8069 could allow an attacker to execute code remotely with the privileges of the NetworkService account.
Is CVE-2024-8069 being actively exploited?
There have been reports and alerts indicating potential active exploitation of CVE-2024-8069.