CVE-2023-38043

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2023
Last modified:
12/08/2024

Description

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:* 22.6 (excluding)
cpe:2.3:a:ivanti:secure_access_client:22.6:r1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*