First published: Tue Nov 14 2023(Updated: )
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Secure Access Client | <22.6 | |
Ivanti Secure Access Client | =22.6-r1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35080 is a vulnerability in the Ivanti Secure Access Windows client that could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks.
CVE-2023-35080 affects Ivanti Secure Access Client version 22.6 and 22.6-r1.
The potential security risks of CVE-2023-35080 include the escalation of privileges, denial of service, or information disclosure.
CVE-2023-35080 has a severity value of 8.8, which is considered high.
To fix CVE-2023-35080, update to the latest version of Ivanti Secure Access Client, which includes security fixes for this vulnerability. Refer to the official Ivanti website for more information on the latest release.