CVE-2024-9842
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
- EPSS probability
- 0.21%
- CWE
- CWE-732, CWE-267
- Published
- 2024-11-12
- Last modified
- 2026-03-13
Affected products
- Ivanti Secure Access Client
Weakness type
Related vulnerabilities
- CVE-2026-87988 — An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace...
- CVE-2026-57843 — NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure
- CVE-2026-84828 — Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
- CVE-2026-19583 — Velociraptor Required Permissions bypass by using client monitoring queries
- CVE-2026-79617 — Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
- CVE-2026-80054 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated...
- CVE-2026-80112 — PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys