Answer in brief
CVE-2024-8068 records a High severity vulnerability in Privilege escalation to NetworkService Account access. The current sources mark it as known exploited. The current feed maps Citrix/Citrix Session Recording (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Citrix/Citrix Session Recording (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Citrix/Citrix Session Recordinggeneric | >=2407 Current Release <24.5.200.8 || >=1912 LTSR <CU9 hotfix 19.12.9100.6 || >=2203 LTSR <CU5 hotfix 22.03.5100.11 || >=2402 LTSR <CU1 hotfix 24.02.1200.16 | 24.5.200.8, CU9 hotfix 19.12.9100.6, CU5 hotfix 22.03.5100.11, CU1 hotfix 24.02.1200.16 |
Published upstream
Nov 12, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 25, 2025
Evidence: source:kev:kev:kev:recordPrivilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-8068 records a High severity vulnerability in Privilege escalation to NetworkService Account access. The current sources mark it as known exploited. The current feed maps Citrix/Citrix Session Recording (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Citrix/Citrix Session Recording (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Citrix/Citrix Session Recordinggeneric | >=2407 Current Release <24.5.200.8 || >=1912 LTSR <CU9 hotfix 19.12.9100.6 || >=2203 LTSR <CU5 hotfix 22.03.5100.11 || >=2402 LTSR <CU1 hotfix 24.02.1200.16 | 24.5.200.8, CU9 hotfix 19.12.9100.6, CU5 hotfix 22.03.5100.11, CU1 hotfix 24.02.1200.16 |
Published upstream
Nov 12, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 25, 2025
Evidence: source:kev:kev:kev:recordPrivilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
Quoted source text, attributed separately from HOL analysis.