First published: Wed Nov 13 2024(Updated: )
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Connect Secure (ICS) VPN | <22.6R2 | |
Ivanti Policy Secure | <22.7R1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39709 is classified as a privilege escalation vulnerability, indicating a high severity level depending on the context of the attack.
To mitigate CVE-2024-39709, upgrade Ivanti Connect Secure to version 22.6R2 or Ivanti Policy Secure to version 22.7R1.
CVE-2024-39709 affects users of Ivanti Connect Secure versions prior to 22.6R2 and Ivanti Policy Secure versions prior to 22.7R1.
CVE-2024-39709 can be exploited by local authenticated attackers to escalate privileges on affected systems.
CVE-2024-39709 is not applicable to Ivanti Connect Secure and Policy Secure versions 9.1Rx.