PT-2024-2911 · Ivanti · Ivanti Avalanche

Published

2024-03-18

·

Updated

2024-07-03

·

CVE-2024-24995

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Avalanche versions prior to 6.4.3
Description A Race Condition (TOCTOU) vulnerability in the web component of Ivanti Avalanche allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. This issue is related to synchronization errors when using a shared resource, specifically a Time-Of-Check Time-Of-Use (TOCTOU) vulnerability. The exploitation of this vulnerability can enable a remote attacker to execute arbitrary commands with SYSTEM privileges.
Recommendations For versions prior to 6.4.3, update to version 6.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the web component of Ivanti Avalanche to minimize the risk of exploitation. Additionally, restrict privileges to the lowest level necessary for operation to reduce the impact of potential exploitation.

Fix

Time Of Check To Time Of Use

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-03076
CVE-2024-24995
ZDI-24-385

Affected Products

Ivanti Avalanche