PT-2024-6661 · Ivanti · Ivanti Workspace Control

Published

2024-09-10

·

Updated

2025-06-12

·

CVE-2024-44103

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ivanti Workspace Control versions 10.18.0.0 and below
Description: The issue is related to DLL hijacking in the management console of Ivanti Workspace Control, which allows a local authenticated attacker to escalate their privileges. This is due to the use of an insecure path search. The exploitation of this issue can enable an attacker to increase their privileges.
Recommendations: For Ivanti Workspace Control versions 10.18.0.0 and below, update to a version above 10.18.0.0 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2024-07863
CVE-2024-44103

Affected Products

Ivanti Workspace Control