CVE-2023-46258: Critical severity ivanti avalanche vulnerability
Published Dec 19, 2023
·Updated
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46258?
CVE-2023-46258 is considered a critical vulnerability due to its potential to cause Denial of Service or enable code execution.
2
How do I fix CVE-2023-46258?
To address CVE-2023-46258, upgrade to Ivanti Avalanche version 6.4.2 or later as recommended in the release notes.
3
What products are affected by CVE-2023-46258?
CVE-2023-46258 affects Ivanti Avalanche versions prior to 6.4.2.
4
Can CVE-2023-46258 lead to remote code execution?
Yes, CVE-2023-46258 can potentially lead to remote code execution due to memory corruption caused by specially crafted data packets.
5
Is Microsoft Windows vulnerable to CVE-2023-46258?
No, Microsoft Windows itself is not vulnerable to CVE-2023-46258, but Ivanti Avalanche running on it can be affected.