Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.
2024-12-11T17:15:14.307
2025-01-23T20:02:22.257
Analyzed
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | performance_manager | < 2023.3 | Yes |
Application | ivanti | performance_manager | 2023.3 | Yes |
Application | ivanti | performance_manager | 2024.1 | Yes |
Application | ivanti | performance_manager | 2024.3 | Yes |