Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
affected
2024.3 HF1 (custom)
unaffected
2024.1 HF2 (custom)
unaffected
2023.3 HF3 (custom)
unaffected
Description
Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
Problem types
CWE-276 Incorrect Default Permissions
Product status
2024.3 HF1 (custom)
2024.1 HF2 (custom)
2023.3 HF3 (custom)
References
forums.ivanti.com/...anti-Application-Control-CVE-2024-11598