CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*

History

12 Aug 2025, 19:04

Type Values Removed Values Added
References () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 - () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 - Mitigation, Vendor Advisory
Summary
  • (es) Los permisos insuficientes en Ivanti Patch SDK anterior a la versión 9.7.703 permiten que un atacante autenticado local elimine archivos arbitrarios.
First Time Ivanti neurons Agent Platform
Ivanti
Ivanti security Controls
Ivanti neurons For Patch Management
Ivanti patch Software Development Kit
Ivanti patch For Configuration Manager
Ivanti endpoint Manager
CPE cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*

10 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 19:15

Updated : 2025-08-12 19:04


NVD link : CVE-2024-10256

Mitre link : CVE-2024-10256

CVE.ORG link : CVE-2024-10256


JSON object : View

Products Affected

ivanti

  • security_controls
  • neurons_for_patch_management
  • patch_software_development_kit
  • patch_for_configuration_manager
  • endpoint_manager
  • neurons_agent_platform
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource