CVE-2019-10885 describes a security bypass vulnerability in Ivanti Workspace Control versions prior to 10.3.90.0. Low-privileged, authenticated local users within a managed session can reset the session context to circumvent configured security features. This vulnerability carries a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, potentially leading to high impact on confidentiality, integrity, and availability. While the EPSS score is low and it is not listed in the KEV catalog, suggesting a low probability of exploitation in the wild, there is no public exploit code available, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.3.90.0CPE matchmatch criteria | cpe:2.3:a:ivanti:workspace_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.