CVE-2024-10630

A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ivantiCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
ivantiapplication_control
𝑥
< 2023.3
ivantiapplication_control
𝑥
< 2023.3
ivantiapplication_control
2023.3
ivantiapplication_control
2023.3:hf1
ivantiapplication_control
2023.3:hf2
ivantiapplication_control
2024.1
ivantiapplication_control
2024.1:hf1
ivantiapplication_control
2024.3
ivantisecurity_controls
𝑥
≤ 2024.4.1
𝑥
= Vulnerable software versions