Vulnerability record · CVE-2024-21888 · published 31 January 2024
CVE-2024-21888: Ivanti Connect Secure and Policy Secure web component privilege escalation
Ivanti · Connect Secure
The web component of Ivanti Connect Secure and Policy Secure (9.x, 22.x) has an improper privilege management flaw that lets an authenticated user elevate to administrator. Because the affected products are remote access gateways, a compromised admin account can expose the whole VPN/ZTNA estate.
Description
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) and very high EPSS (0.868) on an internet-facing remote access gateway, though no KEV listing or known exploit is documented.
What it is
The web component of Ivanti Connect Secure and Policy Secure (9.x, 22.x) has an improper privilege management flaw that lets an authenticated user elevate to administrator. Because the affected products are remote access gateways, a compromised admin account can expose the whole VPN/ZTNA estate.
Impact
An attacker with a low-privileged account gains full administrative control of the appliance, including configuration, user data and policy changes.
Attack surface
Reachable over the network through the web component (AV:N) with low privileges required (PR:L) and no user interaction (UI:N).
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high at 0.868 (99.7th percentile), indicating elevated likelihood of exploitation.
What to do
- Apply the Ivanti vendor advisory fix for Connect Secure and Policy Secure 9.x and 22.x immediately.
- Restrict administrative and web UI access to trusted management networks or VPN-only paths.
- Audit and remove unnecessary low-privileged accounts on the appliances.
- Enable and forward appliance audit logs to a central SIEM for privilege-change monitoring.
- Rotate credentials and review admin accounts for unauthorized changes after patching.
Detection
- Alert on new or modified administrator accounts and role changes in Ivanti appliance logs.
- Monitor for low-privileged sessions invoking administrative endpoints or functions in the web component.
- Correlate web UI access from unusual source IPs with subsequent admin actions.
- Review authentication logs for privilege escalation sequences around the same session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-21888 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-21888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.