CVE-2024-39709: Ivanti Connect Secure

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.

Affected products

  • Ivanti Connect Secure: before 9.1 (fixed in 9.1); from 21.9, before 22.6 (fixed in 22.6); version 9.1 only; version 22.6 only
  • Ivanti Policy Secure: before 9.1 (fixed in 9.1); from 22.1, before 22.7 (fixed in 22.7); version 9.1 only; version 22.7 only

Published 2024-11-13. Last modified 2026-06-17.