CVE-2024-47906

Excessive binary privileges in Ivanti Connect Secure which affects versions 22.4R2 through 22.7R2.2 inclusive within the R2 release line and Ivanti Policy Secure before version 22.7R1.2 allow a local authenticated attacker to escalate privileges.
Configurations

No configuration.

History

13 Nov 2024, 17:01

Type Values Removed Values Added
Summary
  • (es) Los privilegios binarios excesivos en Ivanti Connect Secure, que afectan a las versiones 22.4R2 a 22.7R2.2 inclusive dentro de la línea de lanzamiento R2 y a Ivanti Policy Secure anterior a la versión 22.7R1.2, permiten que un atacante autenticado local escale privilegios.

12 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 16:15

Updated : 2024-11-13 17:01


NVD link : CVE-2024-47906

Mitre link : CVE-2024-47906

CVE.ORG link : CVE-2024-47906


JSON object : View

Products Affected

No product.

CWE
CWE-267

Privilege Defined With Unsafe Actions

CWE-426

Untrusted Search Path