CVE-2023-46264: Malicious File Upload
Published Dec 19, 2023
·Updated
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
Affected Software
2 affected components
All of the following
Ivanti Avalanche<6.4.2
Microsoft Windows
Event History
Dec 19, 2023
CVE Published
03:43 PM
Data Sourced
03:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-46264?
CVE-2023-46264 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2023-46264?
To fix CVE-2023-46264, upgrade Ivanti Avalanche to version 6.4.2 or above.
3
What versions of Ivanti Avalanche are affected by CVE-2023-46264?
Ivanti Avalanche versions 6.4.1 and below are affected by CVE-2023-46264.
4
What type of vulnerability is CVE-2023-46264?
CVE-2023-46264 is an unrestricted file upload vulnerability that could lead to remote code execution.
5
Can CVE-2023-46264 affect operating systems other than Windows?
No, CVE-2023-46264 is specifically related to Ivanti Avalanche running on Microsoft Windows.