Incorrect default permissions in Patch SDK - CVE-2024-10256
Published: December 27, 2024
Vulnerability identifier: #VU101967
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10256
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to delete arbitrary files on the system.
The vulnerability exists due to incorrect default permissions. A local user can delete arbitrary files on the system.
Affected software
Patch SDK
Endpoint Manager
Ivanti Security Controls
Patch for Configuration Manager
Neurons for Patch Management
Neurons Agent Platform
Endpoint Manager
Ivanti Security Controls
Patch for Configuration Manager
Neurons for Patch Management
Neurons Agent Platform
How to mitigate CVE-2024-10256
Install updates from vendor's website.
Patch SDK - update to 9.7.703
Endpoint Manager - addressed in versions 2022 SU6, 2022 SU6 November Update
Ivanti Security Controls - update to 2024.4
Patch for Configuration Manager - update to 2024.4
Neurons for Patch Management - update to 2024.4
Neurons Agent Platform - update to 2024.4
Endpoint Manager - addressed in versions 2022 SU6, 2022 SU6 November Update
Ivanti Security Controls - update to 2024.4
Patch for Configuration Manager - update to 2024.4
Neurons for Patch Management - update to 2024.4
Neurons Agent Platform - update to 2024.4
External References
Related Security Bulletins
- Arbitrary file deletion in Ivanti Patch SDK
- Ivanti Endpoint Manager update for Patch SDK
- Ivanti Security Controls update for Patch SDK
- Ivanti Patch for Configuration Manager update for Patch SDK
- Ivanti Neurons for Patch Management update for Patch SDK
- Ivanti Neurons Agent Platform update for Patch SDK