CVE-2024-9167: Ivanti Velocity License Server
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
Affected products
- Ivanti Velocity License Server: from 5.1, before 5.2 (fixed in 5.2)
Published 2024-10-08. Last modified 2026-06-17.