High severity7.1NVD Advisory· Published Dec 10, 2024· Updated Jun 17, 2026
CVE-2024-10256
CVE-2024-10256
Description
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Affected products
20cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:ivanti:endpoint_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su1:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su2:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su3:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su4:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su5:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2022:su6:*:*:*:*:*:*
- cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
- cpe:2.3:a:ivanti:neurons_for_patch_management:*:*:*:*:*:*:*:*Range: <2024.4
- cpe:2.3:a:ivanti:patch_for_configuration_manager:*:*:*:*:*:*:*:*Range: <2024.4
- cpe:2.3:a:ivanti:patch_software_development_kit:*:*:*:*:*:*:*:*Range: <9.7.703
cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ivanti:security_controls:*:*:*:*:*:*:*:*range: <2024.4
- (no CPE)range: 2024.4
- Range: 2024 November Security Update
- Ivanti/Neurons Agent Platformv5Range: 2024.4
- Ivanti/Neurons for Patch Managementv5Range: 2024.4
- Ivanti/Patch for Configuration Managerv5Range: 2024.4
Patches
Vulnerability mechanics
References
1- forums.ivanti.com/s/article/Security-Advisory-Ivanti-Patch-SDK-CVE-2024-10256nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.