CVE-2024-8069 is a critical remote code execution vulnerability affecting Citrix Session Recording, allowing an authenticated attacker on the same intranet to execute code with NetworkService Account privileges. With a CVSS score of 8.0 (HIGH), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and recent media coverage, despite a lack of public exploit code. The high EPSS score and community discussion indicate widespread awareness and concern regarding its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2407CPE matchmatch criteria | cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:* | ||
1912CPE matchmatch criteria | cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.