A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release - Vendor Advisory | |
References | () https://northwave-cybersecurity.com/vulnerability-notice/arbitrary-kernel-function-call-in-ivanti-secure-access-client - |
12 Aug 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 |
23 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system. |
22 Nov 2023, 15:07
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
Microsoft
Ivanti Ivanti secure Access Client Microsoft windows |
|
References | () https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release - Vendor Advisory | |
CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:secure_access_client:22.6:r1:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo |
15 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-15 00:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-38043
Mitre link : CVE-2023-38043
CVE.ORG link : CVE-2023-38043
JSON object : View
Products Affected
ivanti
- secure_access_client
microsoft
- windows
CWE