CVE-2024-10630: Race Condition
Published Jan 14, 2025
·Updated
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.
Affected Software
10 affected components
Ivanti Application Control Engine<10.14.4.0
Ivanti Application Control<2023.3
Ivanti Application Control<2023.3
Ivanti Application Control=2023.3
Ivanti Application Control=2023.3-hf1
Ivanti Application Control=2023.3-hf2
Ivanti Application Control=2024.1
Ivanti Application Control=2024.1-hf1
Ivanti Application Control=2024.3
Ivanti Security Controls<=2024.4.1
Event History
Jan 14, 2025
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-10630?
CVE-2024-10630 is considered a high-severity vulnerability due to its ability to allow local authenticated attackers to bypass application blocking functionalities.
2
How do I fix CVE-2024-10630?
To fix CVE-2024-10630, upgrade Ivanti Application Control Engine to version 10.14.4.0 or later.
3
Who is affected by CVE-2024-10630?
CVE-2024-10630 affects users of Ivanti Application Control Engine versions prior to 10.14.4.0.
4
What type of attack does CVE-2024-10630 enable?
CVE-2024-10630 enables local authenticated attackers to bypass application control measures.
5
When was CVE-2024-10630 disclosed?
CVE-2024-10630 was disclosed in the year 2024.