NA

CVE-2023-38041

Published: 25/10/2023 Updated: 31/10/2023
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 0

Vulnerability Summary

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ivanti secure_access_client

Github Repositories

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

CVE-2023-38041-POC Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept