PT-2024-8514 · Citrix · Citrix Virtual Apps/Desktops

Published

2024-11-12

·

Updated

2025-08-26

·

CVE-2024-8069

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Citrix Session Recording (affected versions not specified)

**Description:**

A limited remote code execution issue exists in Citrix Session Recording. Successful exploitation allows an attacker with authenticated access on the same intranet as the session recording server to gain access with the privileges of a NetworkService Account. The issue is due to a deserialization of untrusted data flaw. This vulnerability is actively exploited in real-world attacks.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10074
CVE-2024-8069

Affected Products

Citrix Virtual Apps/Desktops