QID 378898
Date Published: 2023-10-23
QID 378898: Ivanti Secure Access Client (SAC) Local Privilege Escalation Vulnerability
A logged in Windows user can leverage functionality of the Pulse Secure / Ivanti Secure Access Client or Pulse Secure Installer Service to carry out a privilege escalation on the user machine.
Affected Versions:
Secure Access Client - 22.3R2 and, below
QID Detection Logic (Authenticated):
This QID checks the vulnerable file version using the registry key
This exploit could allow attacker in theft of sensitive information, disruption of operations, and reputational damage.
Solution
Refer to Ivanti Advisory Ivanti Security Updates for additional information on obtaining the fixes.
Vendor References
CVEs related to QID 378898
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Ivanti Security Adivsory |
|