Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-8069 Details

Description

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Citrix Session Recording Deserialization of Untrusted Data VulnerabilityAug 25, 2025Sep 15, 2025Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-502Deserialization of Untrusted Data[email protected]

Affected Products

ProductVersions
citrix session recording
< 2407
1912 -
1912 cu1
1912 cu2
1912 cu3

CPE

  • cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2402:-:*:*:ltsr:*:*:*
  • cpe:2.3:a:citrix:session_recording:2407:-:*:*:-:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-8069
NVD Published Date:
Nov 12, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-8069 Details - Not Deferred