CVE-2023-38041: Ivanti Secure Access Client
High severity, CVSS 7.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
Affected products
- Ivanti Secure Access Client: before 22.6 (fixed in 22.6)
Published 2023-10-25. Last modified 2026-06-17.