CVE-2024-7572: High severity ivanti desktop and server management vulnerability
Published Dec 10, 2024
·Updated
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
Affected Software
2 affected components
Ivanti DSM<2024.3.5740
Ivanti Desktop \& Server Management>=2024.2<2024.3.5740
Event History
Dec 10, 2024
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-7572?
CVE-2024-7572 is classified as a high severity vulnerability due to the potential for authenticated attackers to delete arbitrary files.
2
How do I fix CVE-2024-7572?
To fix CVE-2024-7572, upgrade Ivanti DSM to version 2024.3.5740 or later.
3
What type of attacker can exploit CVE-2024-7572?
CVE-2024-7572 can be exploited by a local authenticated attacker.
4
What versions of Ivanti DSM are affected by CVE-2024-7572?
CVE-2024-7572 affects Ivanti DSM versions prior to 2024.3.5740.
5
What is the potential impact of CVE-2024-7572 exploitation?
Exploitation of CVE-2024-7572 allows attackers to delete arbitrary files on the system.