CVE-2024-8069
9.5 CISA KEVCitrix · Session Recording
A deserialization of untrusted data vulnerability in Citrix Session Recording allows authenticated network-adjacent users to achieve limited remote code execution via a NetworkService account.
Executive summary
This critical deserialization vulnerability in Citrix Session Recording is currently being exploited in the wild, posing a significant risk of unauthorized code execution to affected environments.
Vulnerability
The flaw involves improper deserialization of untrusted data, which can be triggered by an authenticated user located on the same intranet as the session recording server. Successful exploitation allows the attacker to execute code with the privileges of a NetworkService account.
Business impact
While the CVSS score is 9.5, the urgency is elevated by its inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation could lead to unauthorized system access and potential lateral movement within the intranet, resulting in significant operational disruption or data compromise.
Remediation
Immediate Action: Update Citrix Session Recording to the patched versions: 2407 hotfix 24.5.200.8, 1912 LTSR CU9 hotfix 19.12.9100.6, 2203 LTSR CU5 hotfix 22.03.5100.11, or 2402 LTSR CU1 hotfix 24.02.1200.16.
Proactive Monitoring: Monitor server logs for suspicious deserialization attempts or unusual process execution patterns originating from authenticated internal user accounts.
Compensating Controls: Restrict network access to the Session Recording server to only authorized administrators and implement internal network segmentation to limit the reach of potential internal threat actors.
Exploitation status
Public Exploit Available: Yes, public proof-of-concept repositories are available on GitHub.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of the vulnerability, organizations must prioritize patching immediately. Administrators should verify their current version of Citrix Session Recording against the affected list and apply the specified hotfixes without delay to neutralize this active threat.