CVE-2019-17066: Ivanti Workspace Control
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.
Affected products
- Ivanti Workspace Control: before 10.4.40.0 (fixed in 10.4.40.0)
Published 2020-05-18. Last modified 2026-06-17.