CVE-2023-38041
25.10.2023, 18:17
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
Vendor | Product | Version |
---|---|---|
ivanti | secure_access_client | 𝑥 < 22.6 |
𝑥
= Vulnerable software versions
References