7.8

CVE-2024-11598

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IvantiApplication Control Version <= 2023.3
IvantiApplication Control Version2023.3
IvantiApplication Control Version2023.3 Updatehf1
IvantiApplication Control Version2023.3 Updatehf2
IvantiApplication Control Version2024.1
IvantiApplication Control Version2024.1 Updatehf1
IvantiApplication Control Version2024.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.568
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3c1d8aa1-5a33-4ea4-8992-aadd6440af75 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.