A vulnerability has been discovered in Citrix Session Recording. Refer below for further details:
The following supported versions of Citrix Session Recording are affected by the vulnerability:
Citrix Session Recording before 2407 hotfix 24.5.200.8
Long Term Service Release (LTSR)
Citrix Session Recording 1912 LTSR before CU9 hotfix 19.12.9100.6
Citrix Session Recording 2203 LTSR before CU5 hotfix 22.03.5100.11
Citrix Session Recording 2402 LTSR before CU1 hotfix 24.02.1200.16
Citrix Session Recording contains the vulnerabilities mentioned below:
CVE ID | Description | Pre-requisites | CWE | CVSS |
CVE-2024-8068 | Privilege escalation to NetworkService Account access |
Attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain | CWE-269: Improper Privilege Management |
CVSS v4.0 Base Score: 5.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L) |
CVE-2024-8069 | Limited remote code execution with privilege of a NetworkService Account access |
Attacker must be an authenticated user on the same intranet as the session recording server | CWE-502: Deserialization of Untrusted Data |
CVSS v4.0 Base Score: 5.1 (CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N ) |
Cloud Software Group strongly urges affected customers of Citrix Session Recording to install the relevant updated versions of Citrix Session Recording as soon as their upgrade schedule permits:
Current Release (CR)
Citrix Session Recording 2407 hotfix 24.5.200.8 and later
Long Term Service Release (LTSR)
Citrix Session Recording 1912 LTSR CU9 hotfix 19.12.9100.6 and later
Citrix Session Recording 2203 LTSR CU5 hotfix 22.03.5100.11 and later
Citrix Session Recording 2402 LTSR CU1 hotfix 24.02.1200.16 and later
Session Recording hotfixes are available to download at the following links:
Citrix Session Recording 2407 hotfix 24.5.200.8 - https://support.citrix.com/article/CTX692047
Citrix Session Recording 1912 LTSR CU9 hotfix 19.12.9100.6 - https://support.citrix.com/article/CTX692044
Citrix Session Recording 2203 LTSR CU5 hotfix 22.03.5100.11 - https://support.citrix.com/article/CTX692045
Citrix Session Recording 2402 LTSR CU1 hotfix 24.02.1200.16 - https://support.citrix.com/article/CTX692046
Cloud Software Group thanks Sina Kheirkhah from Watchtowr.com for working with us to protect Cloud Software Group customers.
2024-11-12 | Initial Publication |
2024-11-14 | Replaced 'Citrix Virtual Apps and Desktops' with 'Citrix Session Recording' to better reflect the affected product |