Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://forums.ivanti.com/s/article/Security-Advisory-Velocity-License-Server-CVE-2024-9167 | vendor advisory |