In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-18T21:53:20

Updated: 2024-08-05T01:33:17.067Z

Reserved: 2019-10-01T00:00:00

Link: CVE-2019-17066

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-18T22:15:12.703

Modified: 2020-05-20T14:45:58.353

Link: CVE-2019-17066

cve-icon Redhat

No data.