CVE-2024-29821: High severity ivanti desktop and server management vulnerability
Published Oct 18, 2024
·Updated
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
Affected Software
2 affected components
Ivanti DSM<2024.2
Ivanti Desktop \& Server Management<2024.2
Event History
Oct 18, 2024
CVE Published
via MITRE·11:06 PM
Data Sourced
via MITRE·11:06 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29821?
CVE-2024-29821 has a critical severity level due to its potential for code execution with elevated privileges.
2
How do I fix CVE-2024-29821?
To fix CVE-2024-29821, upgrade Ivanti DSM to version 2024.2 or later.
3
Who is affected by CVE-2024-29821?
CVE-2024-29821 affects users running Ivanti DSM versions prior to 2024.2 on the local machine.
4
What are the potential impacts of CVE-2024-29821?
The potential impacts of CVE-2024-29821 include unauthorized code execution and compromise of system integrity.
5
Is there a workaround for CVE-2024-29821?
No specific workarounds are documented for CVE-2024-29821; updating the software is the recommended solution.