Executive brief
Citrix Session Recording is a tool used by organizations to monitor and record user activity within virtual apps and desktops for compliance and troubleshooting. A security vulnerability in this software allows a person who is already logged into the corporate network to gain higher-level administrative permissions on the recording server. If exploited, an attacker could potentially tamper with recordings or gain broader access to the server's resources, compromising the integrity of the monitoring system.
Technical details
An improper privilege management vulnerability (CWE-269) exists in Citrix Session Recording. The flaw allows an authenticated user within the same Windows Active Directory domain as the session recording server to escalate their privileges to the NetworkService account. The attack vector is restricted to the adjacent network, requiring the attacker to be on the same local network or domain. Successful exploitation grants the attacker the permissions associated with the NetworkService account on the affected server. Citrix has released security updates to address this issue across various versions, including Current Release and Long Term Service Release (LTSR) branches.
Affected products
- Citrix Session Recording Before 2407; 1912 LTSR through CU8; 2203 LTSR through CU5; 2402 LTSR
Timeline
- 2024-11-12: disclosed: Initial disclosure by Citrix
- 2025-08-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog