TROYANOSYVIRUS
Voltar para CVEs

CVE-2024-8069

HIGHCISA KEV
8.0

Descricao

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

Detalhes CVE

Pontuacao CVSS v3.18.0
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueADJACENT_NETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado11/12/2024
Ultima modificacao10/24/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorCitrix
ProdutoSession Recording
Nome da vulnerabilidadeCitrix Session Recording Deserialization of Untrusted Data Vulnerability
Data inclusao KEV2025-08-25
Prazo de remediacao2025-09-15
Uso em ransomwareUnknown

Produtos afetados

citrix:session_recording

Fraquezas (CWE)

CWE-502

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.