CVE-2024-10251: High severity ivanti security controls vulnerability
Published Dec 11, 2024
·Updated
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
Affected Software
1 affected component
Ivanti Security Controls<2024.4.1
Event History
Dec 11, 2024
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10251?
CVE-2024-10251 has a medium severity rating, indicating a significant risk of local privilege escalation.
2
How do I fix CVE-2024-10251?
To mitigate CVE-2024-10251, upgrade Ivanti Security Controls to version 2024.4.1 or later.
3
Who is affected by CVE-2024-10251?
CVE-2024-10251 affects all versions of Ivanti Security Controls prior to 2024.4.1.
4
What type of vulnerability is CVE-2024-10251?
CVE-2024-10251 is a local privilege escalation vulnerability caused by insecure permissions.
5
Can an attacker exploit CVE-2024-10251 remotely?
No, CVE-2024-10251 requires local authenticated access for exploitation.