PT-2024-6586 · Ivanti · Ivanti Workspace Control

CVE-2024-44106

·

Published

2024-09-10

·

Updated

2024-09-18

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ivanti Workspace Control versions 10.18.0.0 and below
Description: The issue is related to insufficient server-side controls in the management console of Ivanti Workspace Control, which can be exploited by a local authenticated attacker to escalate their privileges. This is due to the implementation of security functions on the client-side. The exploitation of this issue may allow an attacker to increase their privileges.
Recommendations: For Ivanti Workspace Control versions 10.18.0.0 and below, update to a version above 10.18.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the management console to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07732
CVE-2024-44106

Affected Products

Ivanti Workspace Control