Vulnerabilities
Vulnerable Software
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
CVSS Score
7.5
EPSS Score
0.016
Published
2021-12-15
An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.
CVSS Score
7.8
EPSS Score
0.003
Published
2021-09-01
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-05-18
Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).
CVSS Score
5.5
EPSS Score
0.002
Published
2020-04-04
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that should be blocked.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-12-17
An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-04-05
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-10-15
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.
CVSS Score
7.8
EPSS Score
0.003
Published
2018-10-15
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-10-15


Contact Us

Shodan ® - All rights reserved