PT-2024-2908 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2025-05-06

·

CVE-2024-27975

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description The issue is related to a use-after-free vulnerability in the WLAvalancheService component of the Ivanti Avalanche mobile device management system. This vulnerability is associated with the use of memory after it has been freed. Exploitation of this issue may allow a remote attacker to execute arbitrary commands with SYSTEM privileges.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the WLAvalancheService component to minimize the risk of exploitation.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-03073
CVE-2024-27975
ZDI-24-391

Affected Products

Ivanti Avalanche