CVE-2024-10630
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.23%
- CWE
- CWE-366
- Published
- 2025-01-14
- Last modified
- 2026-03-13
Affected products
- Ivanti Application Control Engine
Weakness type
Related vulnerabilities
- CVE-2026-3904 — Calling NSS-backed functions that support caching via nscd may call the...
- CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud
- CVE-2026-22819 — Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2024-2032 — Race Condition Vulnerability in zenml-io/zenml
- CVE-2023-6546 — Kernel: gsm multiplexing race condition leads to privilege escalation
- CVE-2023-39198 — Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
- CVE-2023-4732 — Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h