CVE-2023-35080
HIGH 8.8EPSS 0.7%
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS
- 0.71% chance of exploitation in the next 30 days, 51th percentile
- Published
- 2023-11-14
- Updated
- 2025-01-07
Proof-of-concept exploits (2)
- HopHouse/Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation1★ · 2024-02-10
- tijme/ivanti-cve-2023-35080-privilege-escalation-bof2★ · 2023-12-05