Ivanti
Ivanti Workspace Control: vulnerabilidades y CVE
Ivanti Workspace Control tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-5353 | Alta (7.8) | 0.38% | — | 10 jun 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. |
| CVE-2025-22463 | Alta (7.3) | 0.36% | — | 10 jun 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password. |
| CVE-2025-22455 | Alta (7.8) | 0.38% | — | 10 jun 2025 | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials. |
| CVE-2024-8496 | Alta (7.8) | 0.21% | — | 11 dic 2024 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation. |
| CVE-2024-8012 | Alta (7.8) | 0.27% | — | 10 sept 2024 | An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. |
| CVE-2024-44107 | Alta (7.8) | 0.27% | — | 10 sept 2024 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution. |
| CVE-2024-44106 | Alta (7.8) | 0.24% | — | 10 sept 2024 | Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. |
| CVE-2024-44105 | Alta (7.8) | 0.16% | — | 10 sept 2024 | Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials. |
| CVE-2024-44104 | Alta (7.8) | 0.24% | — | 10 sept 2024 | An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to… |
| CVE-2024-44103 | Alta (7.8) | 0.24% | — | 10 sept 2024 | DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges. |
| CVE-2022-21823 | Media (5.5) | 0.35% | — | 10 ene 2022 | A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an… |
| CVE-2019-19138 | Alta (7.5) | 2.1% | — | 15 dic 2021 | Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity. |
| CVE-2021-36235 | Alta (7.8) | 0.72% | — | 1 sept 2021 | An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the… |
| CVE-2019-17066 | Alta (7.8) | 0.47% | — | 18 may 2020 | In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when… |
| CVE-2020-11533 | Media (5.5) | 0.48% | — | 4 abr 2020 | Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material). |
| CVE-2019-16382 | Crítica (9.8) | 2.9% | — | 19 mar 2020 | An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid XML file can then be… |
| CVE-2019-19675 | Alta (7.8) | 0.47% | — | 17 dic 2019 | In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is… |
| CVE-2019-10885 | Alta (7.8) | 1.0% | — | 5 abr 2019 | An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for… |
| CVE-2018-15593 | Alta (7.8) | 1.0% | — | 15 oct 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack… |
| CVE-2018-15592 | Alta (7.8) | 0.59% | — | 15 oct 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector. |
| CVE-2018-15591 | Alta (7.8) | 1.3% | — | 15 oct 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple… |
| CVE-2018-15590 | Media (5.5) | 0.99% | — | 15 oct 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file and folder security restriction by… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.