High severity7.8NVD Advisory· Published May 18, 2020· Updated Jun 17, 2026
CVE-2019-17066
CVE-2019-17066
Description
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.
Affected products
3<10.4.40.0+ 1 more
- (no CPE)range: <10.4.40.0
- cpe:2.3:a:ivanti:workspace_control:*:*:*:*:*:*:*:*range: <10.4.40.0
- Ivanti/WorkSpace Controldescription
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.