CVE-2024-10256: Ivanti Endpoint Manager
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
Affected products
- Ivanti Endpoint Manager: version 2022 only; version 2024 only
- Ivanti Neurons Agent Platform: before 2024.4 (fixed in 2024.4)
- Ivanti Neurons For Patch Management: before 2024.4 (fixed in 2024.4)
- Ivanti Patch For Configuration Manager: before 2024.4 (fixed in 2024.4)
- Ivanti Patch Software Development Kit: before 9.7.703 (fixed in 9.7.703)
- Ivanti Security Controls: before 2024.4 (fixed in 2024.4)
Published 2024-12-10. Last modified 2026-06-17.