VYPR
High severity7.8NVD Advisory· Published May 18, 2020· Updated Jun 17, 2026

CVE-2019-17066

CVE-2019-17066

Description

In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

Affected products

3
  • Ivanti/Workspace Controlllm-fuzzy2 versions
    <10.4.40.0+ 1 more
    • (no CPE)range: <10.4.40.0
    • cpe:2.3:a:ivanti:workspace_control:*:*:*:*:*:*:*:*range: <10.4.40.0
  • Ivanti/WorkSpace Controldescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.