Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
2024-12-11T17:15:14.453
2025-01-23T20:12:36.087
Analyzed
3c1d8aa1-5a33-4ea4-8992-aadd6440af75
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ivanti | application_control | ≤ 2023.3 | Yes |
Application | ivanti | application_control | 2023.3 | Yes |
Application | ivanti | application_control | 2023.3 | Yes |
Application | ivanti | application_control | 2023.3 | Yes |
Application | ivanti | application_control | 2024.1 | Yes |
Application | ivanti | application_control | 2024.1 | Yes |
Application | ivanti | application_control | 2024.3 | Yes |