First published: Fri Oct 18 2024(Updated: )
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Desktop and Server Management | <2024.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29821 has a critical severity level due to its potential for code execution with elevated privileges.
To fix CVE-2024-29821, upgrade Ivanti DSM to version 2024.2 or later.
CVE-2024-29821 affects users running Ivanti DSM versions prior to 2024.2 on the local machine.
The potential impacts of CVE-2024-29821 include unauthorized code execution and compromise of system integrity.
No specific workarounds are documented for CVE-2024-29821; updating the software is the recommended solution.