A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2024-8068

Citrix Session Recording Improper Privilege Management Vulnerability

Published
2025-08-25
Modified
2026-07-31
Sources
cisa-kev

Summary

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.