Skip to main content

Citrix Releases Security Updates for Session Recording

Advisory addresses two vulnerabilities that could allow privilege escalation and remote code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Advisory addresses two vulnerabilities that could allow privilege escalation and remote code execution


Threat details

Exploitation of CVE-2024-8068 and CVE-2024-8069

Security researchers have observed exploitation of CVE-2024-8068 and CVE-2024-8069 in the wild. A public proof-of-concept exploit and a technical analysis of the vulnerabilities has also been published. This information may be used by attackers to target these vulnerabilities in an exploit chain, increasing the likelihood of successful exploitation.


Introduction

Citrix has released a security advisory to address two vulnerabilities in Session Recording.  Citrix Session Recording is a feature of Virtual Apps and Desktops, which is a virtual desktop infrastructure (VDI) solution, providing users with a secure desktop experience on any device. 


Vulnerability Details

  • CVE-2024-8068 is an 'improper privilege management' vulnerability in Session Recording with a CVSSv4 score of 5.1, which if exploited could allow a remote, authenticated attacker to perform privilege escalation to the NetworkService account.
  • CVE-2024-8069 is a 'deserialisation of untrusted data' vulnerability in Session Recording with a CVSSv4 score of 5.1, which if exploited could allow a remote, authenticated attacker to execute arbitrary code on the session recording server.
  • CVE-2024-8068 and CVE-2024-8069 can be chained together, allowing a remote, authenticated attacker to perform remote code execution on the underlying server with SYSTEM privileges
  • Security researchers are claiming that CVE-2024-8068 and CVE-2024-8069 do not require authentication to exploit. If this claim is true, a remote, unauthenticated attacker could execute arbitrary code with SYSTEM privileges on the Virtual Apps and Desktops server.

Threat updates

Date Update
15 Nov 2024 Replaced 'Citrix Virtual Apps and Desktops' with 'Citrix Session Recording' to better reflect the affected product, according to the revised Citrix advisory.

Remediation advice

Affected organisations are strongly encouraged to review Citrix Security Bulletin CTX691941 and apply the relevant updates as soon as practicable.



Last edited: 15 November 2024 2:01 pm