CVE-2023-38041: Ivanti Secure Access Client

High severity, CVSS 7.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

Affected products

  • Ivanti Secure Access Client: before 22.6 (fixed in 22.6)

Published 2023-10-25. Last modified 2026-06-17.