Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 15, 2025

CVE-2024-8068

High
EPSS 8.1%CISA KEV
Citrix/Session Recording

Description

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

EPSS — Exploit Probability

8.1%

Higher than 92.0% of all CVEs

Required Action

https://support.citrix.com/external/article/691941/citrix-session-recording-security-bullet.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-8068

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
8.1%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Aug 25, 2025

Added to KEV

Aug 25, 2025

Remediation Due

Sep 15, 2025

Affected Product

Citrix

Session Recording

View all Citrix CVEs