High severity7.0NVD Advisory· Published Oct 25, 2023· Updated Jun 17, 2026
CVE-2023-38041
CVE-2023-38041
Description
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
Affected products
3cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:*range: <22.6
- (no CPE)range: 22.6R1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.