Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
References
Link | Resource |
---|---|
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Aug 2025, 19:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ivanti endpoint Manager
Ivanti patch Software Development Kit Ivanti neurons For Patch Management Ivanti security Controls Ivanti patch For Configuration Manager Ivanti neurons Agent Platform Ivanti |
|
Summary |
|
|
References | () https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256 - Mitigation, Vendor Advisory | |
CPE | cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:* cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:neurons_agent_platform:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:* cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:* |
10 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-10 19:15
Updated : 2025-08-12 19:04
NVD link : CVE-2024-10256
Mitre link : CVE-2024-10256
CVE.ORG link : CVE-2024-10256
JSON object : View
Products Affected
ivanti
- patch_for_configuration_manager
- security_controls
- endpoint_manager
- neurons_for_patch_management
- neurons_agent_platform
- patch_software_development_kit
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource