CVE-2024-9420: Use After Free
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9
and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9420?
CVE-2024-9420 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2024-9420?
To fix CVE-2024-9420, upgrade Ivanti Connect Secure and Ivanti Policy Secure to versions 22.7R2.3, 22.7R1.2, or later.
Who is affected by CVE-2024-9420?
CVE-2024-9420 affects users of Ivanti Connect Secure versions before 22.7R2.3 and Ivanti Policy Secure versions before 22.7R1.2.
What kind of attack can exploit CVE-2024-9420?
CVE-2024-9420 can be exploited by a remote authenticated attacker to execute arbitrary code.
What should I do if I cannot immediately patch CVE-2024-9420?
If you cannot immediately patch CVE-2024-9420, consider implementing additional security measures such as firewalls and monitoring user access.