Permissions Flaw in Ivanti Secure Access Client
CVE-2024-9842

3.3LOW

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
12 November 2024

Summary

The Ivanti Secure Access Client prior to version 22.7R4 exhibits a permissions issue that enables a local authenticated attacker to create arbitrary folders within the application’s directory, potentially compromising system integrity and user data. This vulnerability underscores the necessity for users to update their software to the latest version to mitigate the risk.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.