logo

Citrix 'Recording Manager' Zero-Day Bug Allows Unauthenticated RCE

ID: 26ce6b31-03d5-5b99-acc1-f60841fc51ca

STIX ID: report--26ce6b31-03d5-5b99-acc1-f60841fc51ca

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-11-12

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

watchTowr researchers disclosed a zero-day in Citrix Session Recording Manager that leverages insecure .NET BinaryFormatter deserialization combined with an exposed MSMQ service and misconfigured permissions to enable unauthenticated remote code execution; the flaw risks data theft and lateral movement from systems that record user activity. Citrix has since issued patches and assigned CVEs, and there were no confirmed in-the-wild exploits reported at the time of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.