CVE-2024-8068 is a privilege escalation vulnerability in Citrix Session Recording that allows an authenticated Active Directory domain user to escalate privileges to NetworkService Account level. Despite being in CISA KEV, this requires existing domain authentication and adjacent network access, making it primarily useful for lateral movement rather than initial access.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2024-11-12
Added to CISA KEV: 2025-08-25 286 DAYS BETWEEN CVE AND KEV
CVE-2024-8068 is a security vulnerability affecting Citrix Session Recording that allows for local privilege escalation [1].
Below is a summary of the known details regarding this vulnerability:
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active ... Official websites use .gov A .gov website belongs to an official government organization in the United States. ... CVE-2024-8068 Detail. Descript…
The CVEs associated with the vulnerabilities are CVE-2024-8068 and CVE-2024-8069 which are currently classified as Medium severity by the vendor ; h owever, this medium rating is disputed by the original author due to the Unauthenticated R emote C ode E xecution capabilities of the exploit on affect…
CVE-2024-8068, Privilege escalation to NetworkService Account access. Attacker must be an authenticated user in the same Windows Active ...