Privilege Escalation Vulnerability in EPM 2022 by Ivanti
CVE-2023-28323
9.8CRITICAL
What is CVE-2023-28323?
The vulnerability exists in EPM 2022 Su3 and all prior versions, allowing unauthenticated users to modify data through the deserialization of untrusted input. This flaw could enable attackers to elevate their privileges, potentially combining it with other operating system vulnerabilities to gain higher access rights on the machine. Furthermore, it can serve as a foothold for accessing other devices within the network, posing significant security risks.
Affected Version(s)
Ivanti Endpoint Manager 2022