CVE-2024-11597

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 11, 2024
CWE ID 276

Summary

CVE-2024-11597 is a newly disclosed vulnerability affecting Ivanti Performance Manager. This issue, occurring in versions 2024.3 HF1, 2024.1 HF1, and 2023.3 HF1, allows local authenticated attackers to escalate privileges due to insecure permissions. By taking advantage of these vulnerabilities, attackers can potentially gain elevated access to the affected system, compromising its security. Ivanti strongly recommends users upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share