CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*

History

12 Aug 2025, 19:04

Type Values Removed Values Added
First Time Ivanti endpoint Manager
Ivanti patch Software Development Kit
Ivanti neurons For Patch Management
Ivanti security Controls
Ivanti patch For Configuration Manager
Ivanti neurons Agent Platform
Ivanti
Summary
  • (es) Los permisos insuficientes en Ivanti Patch SDK anterior a la versión 9.7.703 permiten que un atacante autenticado local elimine archivos arbitrarios.
References () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 - () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*

10 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 19:15

Updated : 2025-08-12 19:04


NVD link : CVE-2024-10256

Mitre link : CVE-2024-10256

CVE.ORG link : CVE-2024-10256


JSON object : View

Products Affected

ivanti

  • patch_for_configuration_manager
  • security_controls
  • endpoint_manager
  • neurons_for_patch_management
  • neurons_agent_platform
  • patch_software_development_kit
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource