Vulnerabilities > Ivanti > Secure Access Client > 22.3

DATE CVE VULNERABILITY TITLE RISK
2023-11-15 CVE-2023-35080 Unspecified vulnerability in Ivanti Secure Access Client
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
local
low complexity
ivanti
7.8
2023-11-15 CVE-2023-38043 Unspecified vulnerability in Ivanti Secure Access Client
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
local
low complexity
ivanti
7.8
2023-11-15 CVE-2023-38543 Unspecified vulnerability in Ivanti Secure Access Client
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
local
low complexity
ivanti
7.8
2023-11-15 CVE-2023-38544 Unspecified vulnerability in Ivanti Secure Access Client 22.2/22.3
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings.
local
low complexity
ivanti
5.5
2023-11-15 CVE-2023-41718 Unspecified vulnerability in Ivanti Secure Access Client 22.2/22.3
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
local
low complexity
ivanti
7.8
2023-10-25 CVE-2023-38041 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ivanti Secure Access Client 22.2/22.3/22.5
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition.
local
high complexity
ivanti CWE-367
7.0