Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown
CVE-2024-7571
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2023-38042
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
0
Attacker Value
Unknown
CVE-2024-3661
Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
0
Attacker Value
Unknown
CVE-2023-41718
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
0
Attacker Value
Unknown
CVE-2023-38544
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
0
Attacker Value
Unknown
CVE-2023-38543
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
0
Attacker Value
Unknown
CVE-2023-38043
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
0
Attacker Value
Unknown
CVE-2023-35080
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
0
Attacker Value
Unknown
CVE-2023-38041
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
0
Attacker Value
Unknown
CVE-2023-24492
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
0