ZDI-CAN-23545: ZDI-24-1487: Ivanti Secure Access Client Pulse Secure Service Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Ivanti Secure Access Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-7571.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-23545?
The severity of ZDI-CAN-23545 is associated with privilege escalation risks for local attackers.
How do I fix ZDI-CAN-23545?
To fix ZDI-CAN-23545, apply the latest security patches provided by Ivanti for the Secure Access Client.
Who is affected by ZDI-CAN-23545?
ZDI-CAN-23545 affects installations of the Ivanti Secure Access Client.
What type of vulnerability is ZDI-CAN-23545?
ZDI-CAN-23545 is a privilege escalation vulnerability.
Can ZDI-CAN-23545 be exploited remotely?
No, ZDI-CAN-23545 requires local access to the affected system to be exploited.