Citrix 'Recording Manager' Zero-Day Bug Allows Unauthenticated RCE
ID: 26ce6b31-03d5-5b99-acc1-f60841fc51ca
STIX ID: report--26ce6b31-03d5-5b99-acc1-f60841fc51ca
Feed Name: Dark Reading
Date Published: 2024-11-12
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
watchTowr researchers disclosed a zero-day in Citrix Session Recording Manager that leverages insecure .NET BinaryFormatter deserialization combined with an exposed MSMQ service and misconfigured permissions to enable unauthenticated remote code execution; the flaw risks data theft and lateral movement from systems that record user activity. Citrix has since issued patches and assigned CVEs, and there were no confirmed in-the-wild exploits reported at the time of publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
