Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation
Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation
31 January 2024
Ivanti is alerting of two new high-severity flaws in its Connect Secure and Policy Secure products, one of which is said to have come under targeted exploitation in the wild.
The list of vulnerabilities is as follows -
CVE-2024-21888 (CVSS score: 8.8) - A privilege escalation vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows