Skip to main content

Vendor/product archive

ivanti / workspace_control CVEs

Beta · best-effort

22 CVEs tagged to ivanti / workspace_control1 Critical, 18 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-5353

Published Jun 10, 2025

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-22463

Published Jun 10, 2025

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-22455

Published Jun 10, 2025

A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-8496

Published Dec 11, 2024

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8012

Published Sep 10, 2024

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44107

Published Sep 10, 2024

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achiev…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44106

Published Sep 10, 2024

Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44105

Published Sep 10, 2024

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to o…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44104

Published Sep 10, 2024

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) al…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44103

Published Sep 10, 2024

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21823

Published Jan 10, 2022

A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privil…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36235

Published Sep 1, 2021

An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspeci…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17066

Published May 18, 2020

In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the C…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11533

Published Apr 4, 2020

Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16382

Published Mar 19, 2020

An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19675

Published Dec 17, 2019

In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10885

Published Apr 5, 2019

An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Con…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15593

Published Oct 15, 2018

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15592

Published Oct 15, 2018

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15591

Published Oct 15, 2018

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15590

Published Oct 15, 2018

An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1