Attackers Can Elevate Privileges via DLL Hijacking in Ivanti Workspace Control
CVE-2024-44103
7.8HIGH
Summary
A DLL hijacking vulnerability exists in the management console of Ivanti Workspace Control versions up to 10.18.0.0. This flaw can be exploited by local authenticated attackers, granting them the ability to escalate their privileges within the affected environment. By manipulating the loading of dynamic link libraries, an attacker could execute unauthorized actions, potentially leading to broader system compromises. It is crucial for users of Ivanti Workspace Control to assess their installations and apply necessary mitigations as outlined in the security advisory provided by Ivanti.
Affected Version(s)
Workspace Control 10.18.50.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD DatabaseMitre Database