CVE-2024-8069

HIGH KEV

Citrix Session Recording - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-8069 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 25, 2025. EIP tracks 1 public exploit from researchers including mdiqbalahmad.

AI-analyzed exploit summary This repository contains a Python-based exploit for CVE-2024-8069, targeting Citrix Virtual Apps and Desktops (XEN) with an unauthenticated remote code execution vulnerability. The exploit crafts a malicious MSMQ SOAP request to execute arbitrary commands on the target system.

Description

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

Exploits (1)

nomisec WORKING POC
by mdiqbalahmad · poc
https://github.com/mdiqbalahmad/cve-2024-8069-exp-Citrix-Virtual-Apps-XEN

This repository contains a Python-based exploit for CVE-2024-8069, targeting Citrix Virtual Apps and Desktops (XEN) with an unauthenticated remote code execution vulnerability. The exploit crafts a malicious MSMQ SOAP request to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Citrix Virtual Apps and Desktops 7 2402 LTSR and earlier
No auth needed
Prerequisites: Network access to the target system · Target system running vulnerable Citrix software
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.0
EPSS 0.4829
EPSS Percentile 97.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2025-08-25
VulnCheck KEV 2024-11-12
ENISA EUVD EUVD-2024-48915
CWE
CWE-502
Status published
Products (5)
citrix/session_recording 1912 (9 CPE variants)
citrix/session_recording 2203 (5 CPE variants)
citrix/session_recording 2402
citrix/session_recording 2407
citrix/session_recording < 2407
Published Nov 12, 2024
KEV Added Aug 25, 2025
Tracked Since Feb 18, 2026