Loading HuntDB...

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Added Aug. 25, 2025 Due Sept. 15, 2025 CVE-2024-8069
Overdue Citrix / Session Recording CWE-502

Description

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.08.25
Catalog Released
Aug. 25, 2025
Days Until Due
0 days
Last Updated
3 months ago