Improper privilege management in Citrix Virtual Apps and Desktops - CVE-2024-8068

 

Improper privilege management in Citrix Virtual Apps and Desktops - CVE-2024-8068

Published: November 13, 2024 / Updated: August 25, 2025


Vulnerability identifier: #VU100448
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8068
CWE-ID: CWE-269
Exploitation vector: Adjecent network
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to improper privilege management within the NetworkService Account access. A remote user can escalate privileges on the system.

Note, an attacker must be authenticated in the same Windows Active Directory domain as the session recording server domain.


Affected software

Citrix Virtual Apps and Desktops

How to mitigate CVE-2024-8068

Install updates from vendor's website.

Citrix Virtual Apps and Desktops - addressed in versions 1912 LTSR CU9 hotfix 19.12.9100.6, 2203 LTSR CU5 hotfix 22.03.5100.11, 2402 LTSR CU1 hotfix 24.02.1200.16, 2407 hotfix 24.5.200.8

External References

Related Security Bulletins