Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-38041


A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.


Published

2023-10-25T18:17:28.757

Last Modified

2025-03-07T19:15:35.757

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti secure_access_client < 22.6 Yes
Operating System microsoft windows - No

References