PT-2024-2911 · Ivanti · Ivanti Avalanche
Published
2024-03-18
·
Updated
2024-07-03
·
CVE-2024-24995
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti Avalanche versions prior to 6.4.3
Description
A Race Condition (TOCTOU) vulnerability in the web component of Ivanti Avalanche allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. This issue is related to synchronization errors when using a shared resource, specifically a Time-Of-Check Time-Of-Use (TOCTOU) vulnerability. The exploitation of this vulnerability can enable a remote attacker to execute arbitrary commands with SYSTEM privileges.
Recommendations
For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the web component of Ivanti Avalanche to minimize the risk of exploitation. Additionally, restrict privileges to the lowest level necessary for operation to reduce the impact of potential exploitation.
Fix
Time Of Check To Time Of Use
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ivanti Avalanche