Ivanti Workspace Control Application PowerGrid SEE Whitelist Bypass

Discussion in 'News Aggregator' started by Packet Storm, 2 Oct 2018.

  1. Packet Storm

    Packet Storm Guest

    It was found that the PowerGrid application can be used to run arbitrary commands via the /SEE command line option. An attacker can abuse this issue to bypass Application Whitelisting in order to run arbitrary code on the target machine. This issue was successfully verified on Ivanti Workspace Control version 10.2.950.0.

    Continue reading...
     

Share This Page

Loading...