Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
2024-11-12T18:15:47.603
2025-10-24T13:42:29.560
Analyzed
CVSSv3.1: 8.0 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | citrix | session_recording | < 2407 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 1912 | Yes |
| Application | citrix | session_recording | 2203 | Yes |
| Application | citrix | session_recording | 2203 | Yes |
| Application | citrix | session_recording | 2203 | Yes |
| Application | citrix | session_recording | 2203 | Yes |
| Application | citrix | session_recording | 2203 | Yes |
| Application | citrix | session_recording | 2402 | Yes |
| Application | citrix | session_recording | 2407 | Yes |