CVE-2024-21888: Ivanti Connect Secure privilege escalation to administrator
The short version: CVE-2024-21888 is a privilege-escalation vulnerability in the web component of Ivanti Connect Secure and Ivanti Policy Secure that lets a user elevate to administrator. It landed in the same January-2024 advisory as the widely exploited Connect Secure chain, but on its own it needs a foothold first, and — unlike CVE-2023-46805 and CVE-2024-21887 — it is not listed in CISA's KEV catalog. Patch it with the rest; it's not the five-alarm of the batch. Steady hands.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | Moderate — real, but lower urgency than the KEV-listed chain it shipped alongside |
| CVSS v3.0 (NVD) | 8.8 — High · AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | ~86.8% · 99.72nd percentile (2026-07-17) |
| In CISA KEV? | No |
| Known exploited? | Not confirmed in the wild (no public exploit noted in our source definition) |
| Vulnerability type | Privilege escalation → elevation to administrator |
| Requires authenticated session? | Yes — needs an existing lower-privileged foothold to escalate |
| Affected | Ivanti Connect Secure 9.x and 22.x; Ivanti Policy Secure 9.x and 22.x |
| Fixed in | Patched builds per Ivanti's advisory (published 2024-01-31) |
What you need to know
CVE-2024-21888 lets a user who already has some access to the appliance's web component elevate their privileges to administrator. That's a meaningful jump on a device that terminates remote access — administrator on Connect Secure is control of the gateway.
The honest distinctions from its more famous siblings:
- It needs a starting foothold. This is escalation, not initial access. An attacker has to already be on the appliance in some capacity to use it.
- It's not in KEV. CISA has not added this CVE to the Known Exploited Vulnerabilities catalog, and our source definition doesn't record a public exploit or in-the-wild use — a real difference from CVE-2023-46805 and CVE-2024-21887, which are both KEV-listed and were mass-exploited.
- It travels with the chain. It was disclosed in the same window as the exploited Connect Secure bugs, so if you're patching those, you're patching this too.
How serious we see it
Moderate — genuinely serious on paper, with lower real-world urgency than its neighbors.
An 8.8 privilege escalation to administrator on a perimeter appliance is not something to leave open. But severity is also about likelihood, and here the picture is calmer: it requires a prior foothold, it isn't KEV-listed, and we're not aware of confirmed in-the-wild exploitation. So we rate it High and prioritize it just below the actively exploited chain it shipped with. The reassuring part is that the same patch cycle closes it.
Recommendations
Straight from Ivanti's advisory:
- Patch now, with the rest of the January-2024 set. Apply the fixed builds from Ivanti's advisory for your Connect Secure / Policy Secure version.
- Confirm the actively exploited siblings are handled too. CVE-2023-46805 and CVE-2024-21887 are the KEV-listed, higher-urgency pair — make sure they're patched and hunted.
- Limit who can reach the appliance. Fewer reachable accounts means fewer starting footholds for an escalation bug.
- Harden exposure. Keep the management interface off the public internet.
- Confirm your exposure first. Verify whether you run an affected Connect Secure or Policy Secure build.
How BreachRisk sees it
BreachRisk discovers internet-facing Ivanti Connect Secure and Policy Secure interfaces from little more than your domain, fingerprints the product and version, and flags version-based exposure to this CVE. Because our prioritization reflects KEV status and real-world exploitation, this one is surfaced as a genuine finding but ranked below the actively exploited chain — so your attention lands where the pressure actually is.
That's the value of a continuous, attacker's-eye view: not just a list of CVEs, but exposure sorted by how it's really being used.