CVE-2024-10630: Ivanti Application Control

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.

Affected products

  • Ivanti Application Control: before 2023.3 (fixed in 2023.3); version 2023.3 only; version 2024.1 only; version 2024.3 only
  • Ivanti Security Controls: up to and including 2024.4.1

Published 2025-01-14. Last modified 2026-06-17.