CVE-2023-38041: Race Condition
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38041?
CVE-2023-38041 is a vulnerability that allows a logged-in user to elevate its permissions by exploiting a Time-of-Check to Time-of-Use (TOCTOU) race condition.
What is the severity of CVE-2023-38041?
The severity of CVE-2023-38041 is high, with a severity value of 7.8.
What software is affected by CVE-2023-38041?
Ivanti Secure Access Client versions up to exclusive 22.6 are affected by CVE-2023-38041.
How can an attacker exploit CVE-2023-38041?
An attacker can exploit CVE-2023-38041 by abusing the Time-of-Check to Time-of-Use (TOCTOU) race condition when a particular process flow is initiated.
Is Microsoft Windows affected by CVE-2023-38041?
No, Microsoft Windows is not vulnerable to CVE-2023-38041.
How can I fix CVE-2023-38041?
To fix CVE-2023-38041, it is recommended to update Ivanti Secure Access Client to a version beyond 22.6.