First published: Tue Nov 14 2023(Updated: )
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Ivanti Secure Access Client | <22.6 | |
Ivanti Secure Access Client | =22.6-r1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Ivanti Secure Access Client vulnerability is CVE-2023-38043.
The severity of CVE-2023-38043 is high, with a severity value of 8.8.
All versions of the Ivanti Secure Access Client below 22.6R1.1 are affected by CVE-2023-38043.
CVE-2023-38043 could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
To fix CVE-2023-38043, it is recommended to update the Ivanti Secure Access Client to version 22.6R1.1 or higher.