A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://forums.ivanti.com/s/article/Security-fixes-included-in-the-latest-Ivanti-Secure-Access-Client-Release - Vendor Advisory | |
References | () https://northwave-cybersecurity.com/vulnerability-notice/arbitrary-kernel-function-call-in-ivanti-secure-access-client - |
12 Aug 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-400 |
23 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-15 00:15
Updated : 2024-11-21 08:12
NVD link : CVE-2023-38043
Mitre link : CVE-2023-38043
CVE.ORG link : CVE-2023-38043
JSON object : View
Products Affected
ivanti
- secure_access_client
microsoft
- windows
CWE