PoC Index

CVE-2024-8068

KEVHIGH 8.0EPSS 1.4%

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

CVSS v4.0
5.1 MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.40% chance of exploitation in the next 30 days, 70th percentile
CISA KEV
added 2025-08-25
Published
2024-11-12
Updated
2025-10-21

Proof-of-concept exploits (2)

References

Related