Executive brief
A vulnerability in the Ivanti Secure Access Client, a tool used for secure remote connectivity, could allow a user already logged into a Windows computer to gain full administrative (SYSTEM) control. This type of flaw is typically used by attackers who have already gained a foothold on a machine to deepen their access and disable security protections. Organizations should update the client software to version 22.8R6 or later to prevent this privilege escalation.
Technical details
A race condition (CWE-362) exists in the Ivanti Secure Access Client for Windows prior to version 22.8R6. The vulnerability occurs during concurrent execution using shared resources with improper synchronization, allowing a locally authenticated attacker with low privileges to exploit a timing window to execute code with SYSTEM-level authority. The attack requires local access to the target machine but no user interaction. Ivanti has released version 22.8R6 to address this issue.
Affected products
- Ivanti Secure Access Client before 22.8R6
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched