#VU88772 Out-of-bounds read in Avalanche - CVE-2024-23532
Published: April 17, 2024 / Updated: April 24, 2024
Avalanche
Ivanti
Description
The vulnerability allows a remote attacker to gain user to execute arbitrary code on the system.
The vulnerability exists due to a boundary condition within the WLAvalancheService component. A remote authenticated user can send specially crafted data to the system, trigger an out-of-bounds read error and execute arbitrary code.