CVE-2024-10256: Ivanti Endpoint Manager

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Affected products

  • Ivanti Endpoint Manager: version 2022 only; version 2024 only
  • Ivanti Neurons Agent Platform: before 2024.4 (fixed in 2024.4)
  • Ivanti Neurons For Patch Management: before 2024.4 (fixed in 2024.4)
  • Ivanti Patch For Configuration Manager: before 2024.4 (fixed in 2024.4)
  • Ivanti Patch Software Development Kit: before 9.7.703 (fixed in 9.7.703)
  • Ivanti Security Controls: before 2024.4 (fixed in 2024.4)

Published 2024-12-10. Last modified 2026-06-17.