QID 731165

Date Published: 2024-02-19

QID 731165: Ivanti Connect Secure Privilege Escalation Vulnerability

Ivanti Connect Secure provides a seamless, cost-effective, SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources.

CVE-2023-41720: A vulnerability exists on the 22x branch of Ivanti Connect Secure below 22.6R2 where an attacker can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system.

Affected Versions:
Ivanti Connect Secure 22.x

Patched Versions:
Ivanti Connect Secure 22.5R2.3
Ivanti Connect Secure 22.6R2.2

QID Detection Logic: This QID checks for the installed version of Ivanti Connect Secure (ICS) by sending a GET request to the '/dana-cached/sc/PulseSecureInstallerService.exe' endpoint.

Successful exploitation of the vulnerability may allow a low-privileged user to escalate privileges, leading to data loss and system compromise.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    Customers are advised to upgrade their Ivanti Connect Secure instances to the latest version. For more information, please refer to the Ivanti Security Advisory.

    CVEs related to QID 731165

    Software Advisories
    Advisory ID Software Component Link
    000089503 URL Logo forums.ivanti.com/s/article/Security-patch-release-Ivanti-Connect-Secure-22-6R2-and-22-6R2-1?language=en_US