Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-24-067
HistoryJan 11, 2024 - 12:00 a.m.

Ivanti Avalanche WLAvalancheService Divide By Zero Denial-of-Service Vulnerability

2024-01-1100:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
6
ivanti avalanche
wlavalancheservice
denial of service
vulnerability
integer division operation

AI Score

6.7

Confidence

High

EPSS

0.004

Percentile

73.9%

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The specific flaw exists within the WLAvalancheService. The issue results from the lack of proper exception handling when performing an integer division operation. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

AI Score

6.7

Confidence

High

EPSS

0.004

Percentile

73.9%

Related for ZDI-24-067