cve/2024/CVE-2024-8068.md

20 lines
872 B
Markdown
Raw Normal View History

2025-09-29 16:08:36 +00:00
### [CVE-2024-8068](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8068)
![](https://img.shields.io/static/v1?label=Product&message=Citrix%20Session%20Recording&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=2407%20Current%20Release%3C%2024.5.200.8%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-269%20Improper%20Privilege%20Management&color=brighgreen)
### Description
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/XiaomingX/cve-2024-8069-exp-Citrix-Virtual-Apps-XEN
- https://github.com/XiaomingX/weekly
- https://github.com/opendr-io/causality