Incorrect default permissions in Patch SDK - CVE-2024-10256

 

Incorrect default permissions in Patch SDK - CVE-2024-10256

Published: December 27, 2024


Vulnerability identifier: #VU101967
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10256
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to delete arbitrary files on the system.

The vulnerability exists due to incorrect default permissions. A local user can delete arbitrary files on the system.


Affected software

Patch SDK
Endpoint Manager
Ivanti Security Controls
Patch for Configuration Manager
Neurons for Patch Management
Neurons Agent Platform

How to mitigate CVE-2024-10256

Install updates from vendor's website.

Patch SDK - update to 9.7.703
Endpoint Manager - addressed in versions 2022 SU6, 2022 SU6 November Update
Ivanti Security Controls - update to 2024.4
Patch for Configuration Manager - update to 2024.4
Neurons for Patch Management - update to 2024.4
Neurons Agent Platform - update to 2024.4

External References

Related Security Bulletins