Executive Risk Summary
"A privilege escalation vulnerability in the web component of Ivanti Connect Secure and Ivanti Policy Secure allows a user to elevate privileges to that of an administrator, potentially leading to unauthorized access and control. This vulnerability affects versions 9.x and 22.x of the affected products."
Operational Audit Arsenal
Target Type Web Application
Target Asset web component
Standard Path Global Web Interface
Manual Verification Required
This is a non-Windows asset (Ivanti). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.
Patch Impact Forecast
Reboot Required Likely
Moderate
Internal Work Notes
Privilege escalation vulnerability in Ivanti Connect Secure and Policy Secure web component, requiring immediate patching to prevent unauthorized administrative access.
Technical Intelligence & Operational Utilities • Delivered Weekly
Intelligence Sources
Official Advisoryhttps://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US
Official Advisoryhttps://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US
Related Ivanti Threats
Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.