Privilege Escalation in Citrix Session Recording
CVE-2024-8068

5.1MEDIUM

Key Information:

Vendor

Citrix

Vendor
CVE Published:
12 November 2024

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 1,480πŸ‘Ύ Exploit ExistsπŸ¦… CISA ReportedπŸ“° News Worthy

What is CVE-2024-8068?

CVE-2024-8068 is a serious privilege escalation vulnerability found in Citrix Session Recording, a tool designed for monitoring user sessions in virtual environments to enhance user experience and security. This vulnerability allows an authenticated user within the same Windows Active Directory domain as the session recording server to gain elevated access rights to the NetworkService Account. This unauthorized access can lead to significant breaches in security protocols and the potential for attackers to manipulate sensitive data or systems. Organizations relying on Citrix Session Recording for monitoring and managing user sessions are particularly at risk, as the flaw undermines the security assurances typically provided by the software.

Potential impact of CVE-2024-8068

  1. Unauthorized Access to Sensitive Data: Exploiting this vulnerability could allow malicious actors to elevate their privileges, enabling them to access confidential recordings and sensitive user data stored within the system.

  2. System Integrity Compromise: With elevated privileges, attackers could alter configurations or settings, resulting in broader system vulnerabilities that could be exploited for further attacks or data exfiltration.

  3. Increased Risk of Malware Deployment: The ability to gain access to the NetworkService Account may facilitate the deployment of malware or other malicious activities within the organization's network, heightening the threat landscape and complicating incident response efforts.

CISA has reported CVE-2024-8068

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-8068 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

Citrix Session Recording 2407 Current Release < 24.5.200.8

Citrix Session Recording 1912 LTSR

Citrix Session Recording 2203 LTSR

News Articles

Citrix Virtual Apps & Desktops RCE Vulnerability, PoC Exploitation Underway

Security researchers have disclosed critical vulnerabilities in Citrix Virtual Apps and Desktops that could allow remote code execution (RCE) attacks.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • πŸ¦…

    CISA Reported

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by CyberSecurityNews

  • Vulnerability published

.
CVE-2024-8068 : Privilege Escalation in Citrix Session Recording