CVE-2024-10256 is a local privilege escalation vulnerability in the Ivanti Patch SDK, affecting Ivanti Endpoint Manager, Neurons Agent Platform, Neurons for Patch Management, Patch for Configuration Manager, Patch Software Development Kit, and Security Controls. It allows a local authenticated attacker to delete arbitrary files due to insufficient permissions. Rated 7.1 HIGH CVSS, this vulnerability has low attack complexity and requires local access, but can lead to high impact on integrity and availability. There is no evidence of active exploitation, public exploit code, or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:* | ||
2022CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.