CVE-2024-10256

HIGH

Ivanti Patch SDK <9.7.703 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 10.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (7)
ivanti/endpoint_manager 2022 (7 CPE variants)
ivanti/endpoint_manager 2024
ivanti/neurons_agent_platform < 2024.4
ivanti/neurons_for_patch_management < 2024.4
ivanti/patch_for_configuration_manager < 2024.4
ivanti/patch_software_development_kit < 9.7.703
ivanti/security_controls < 2024.4
Published Dec 10, 2024
Tracked Since Feb 18, 2026