Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
References
| Link | Resource |
|---|---|
| https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-12-10 19:15
Updated : 2025-08-12 19:04
NVD link : CVE-2024-10256
Mitre link : CVE-2024-10256
CVE.ORG link : CVE-2024-10256
JSON object : View
Products Affected
ivanti
- neurons_for_patch_management
- neurons_agent_platform
- patch_for_configuration_manager
- endpoint_manager
- patch_software_development_kit
- security_controls
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
