CVE-2024-10256

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2024
Last modified:
12/08/2025

Description

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:* 2024.4 (excluding)
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:* 2024.4 (excluding)
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:* 2024.4 (excluding)
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:* 9.7.703 (excluding)
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:* 2024.4 (excluding)