CVE-2024-8069 is an adjacent network RCE vulnerability in Citrix Session Recording requiring authenticated intranet access. Despite CISA KEV listing indicating active exploitation, the attack vector is limited to adjacent networks, not direct internet exploitation.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-11-12
Added to CISA KEV: 2025-08-25 286 DAYS BETWEEN CVE AND KEV
CVE-2024-8069 is a security vulnerability affecting Citrix Session Recording [2]. Below is a summary of the known details regarding this vulnerability.
Two Citrix vulnerabilities (CVE-2024-8068 and CVE-2024-8069) can potentially lead to unauthenticated remote code execution. ... Citrix Virtual Apps and Desktops 2402 LTSR before CU1 hotfix 24.02.1200.16. What should I do about CVE-2024-8068 and CVE-2024-8069? IONIX customers will see updated informa…
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user. ... An official website of the United States government Here's how you know ... CVE-2024-8069 Detail. Description. Limited remote code execution with…
XiaomingX / cve-2024-8069-exp-Citrix-Virtual-Apps-XEN Public.
The CVEs associated with the vulnerabilities are CVE-2024-8068 and CVE-2024-8069 which are currently classified as Medium severity by the vendor ; h owever, this medium rating is disputed by the original author due to the Unauthenticated R emote C ode E xecution capabilities of the exploit on affect…
Privileges Required: This metric describes the level of privileges an attacker must possess prior to successfully exploiting the vulnerability. ... References. https://nvd.nist.gov/vuln/detail/CVE-2024-8069. https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-fo…