CVE-2023-38042
- EPSS 0.14%
- Veröffentlicht 31.05.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:12:43
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
CVE-2023-34298
- EPSS 0.12%
- Veröffentlicht 03.05.2024 02:15:30
- Zuletzt bearbeitet 13.08.2025 12:23:38
Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the abilit...
CVE-2023-41718
- EPSS 0.21%
- Veröffentlicht 15.11.2023 00:15:08
- Zuletzt bearbeitet 07.01.2025 19:15:31
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
CVE-2023-38544
- EPSS 0.17%
- Veröffentlicht 15.11.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:47
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
CVE-2023-38543
- EPSS 0.19%
- Veröffentlicht 15.11.2023 00:15:08
- Zuletzt bearbeitet 07.01.2025 19:15:30
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user...
CVE-2023-38043
- EPSS 0.27%
- Veröffentlicht 15.11.2023 00:15:07
- Zuletzt bearbeitet 21.11.2024 08:12:44
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user...
CVE-2023-35080
- EPSS 0.43%
- Veröffentlicht 15.11.2023 00:15:07
- Zuletzt bearbeitet 07.01.2025 19:15:30
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privi...
- EPSS 0.43%
- Veröffentlicht 25.10.2023 18:17:28
- Zuletzt bearbeitet 07.03.2025 19:15:35
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affect...