Race condition within a thread in Ivanti products - CVE-2024-10630
Published: January 15, 2025
Vulnerability identifier: #VU102820
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10630
CWE-ID: CWE-366
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition. A local user can exploit the race and bypass configured protections.
Affected software
Application Control
Ivanti Security Controls
Ivanti Neurons for App Control
Ivanti Security Controls
Ivanti Neurons for App Control
How to mitigate CVE-2024-10630
Install updates from vendor's website.
Application Control - addressed in versions 2023.3 HF3, 2024.1 HF4, 2024.3 HF1