Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://forums.ivanti.com/s/article/December-2024-Security-Advisory-Ivanti-Automation-CVE-2024-9845 | vendor advisory |