Citrix Patches Zero-Day Recording Manager Bugs
ID: 8d20586e-d6a4-5f79-a6cb-443b365fbcb1
STIX ID: report--8d20586e-d6a4-5f79-a6cb-443b365fbcb1
Feed Name: Dark Reading
Threat Score
Citrix released patches for two vulnerabilities in the Session Recording Manager of Virtual Apps and Desktop (CVE-2024-8068, CVE-2024-8069) that stem from BinaryFormatter deserialization and an internet-accessible MSMQ queue; watchTowr published a PoC claiming easy unauthenticated RCE and ShadowServer reported PoC-based exploitation attempts, while Citrix rates the issues as medium severity (CVSS 5.1) and urges customers to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
