CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-10 19:15

Updated : 2025-08-12 19:04


NVD link : CVE-2024-10256

Mitre link : CVE-2024-10256

CVE.ORG link : CVE-2024-10256


JSON object : View

Products Affected

ivanti

  • neurons_for_patch_management
  • neurons_agent_platform
  • patch_for_configuration_manager
  • endpoint_manager
  • patch_software_development_kit
  • security_controls
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource