- EPSS 0.03%
- Veröffentlicht 12.05.2026 14:21:58
- Zuletzt bearbeitet 12.05.2026 19:53:00
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
CVE-2026-7431
- EPSS 0.04%
- Veröffentlicht 12.05.2026 14:18:56
- Zuletzt bearbeitet 12.05.2026 19:53:39
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
CVE-2025-22454
- EPSS 0.28%
- Veröffentlicht 11.03.2025 14:11:30
- Zuletzt bearbeitet 16.07.2025 15:25:26
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
CVE-2024-13813
- EPSS 0.23%
- Veröffentlicht 11.02.2025 16:15:39
- Zuletzt bearbeitet 20.02.2025 15:56:04
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.
CVE-2024-38654
- EPSS 0.06%
- Veröffentlicht 13.11.2024 02:15:18
- Zuletzt bearbeitet 27.06.2025 18:45:18
Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.
CVE-2024-37398
- EPSS 0.36%
- Veröffentlicht 13.11.2024 02:15:18
- Zuletzt bearbeitet 18.11.2024 15:23:23
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
CVE-2024-29211
- EPSS 0.18%
- Veröffentlicht 13.11.2024 02:15:16
- Zuletzt bearbeitet 14.11.2024 19:09:01
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-8539
- EPSS 0.21%
- Veröffentlicht 12.11.2024 17:15:11
- Zuletzt bearbeitet 17.01.2025 20:02:50
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-9843
- EPSS 0.15%
- Veröffentlicht 12.11.2024 17:15:11
- Zuletzt bearbeitet 17.01.2025 20:00:21
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-9842
- EPSS 0.22%
- Veröffentlicht 12.11.2024 17:15:11
- Zuletzt bearbeitet 17.01.2025 19:55:48
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.