Remote Code Execution Vulnerability in Ivanti Endpoint Manager
CVE-2024-13158

7.2HIGH

Key Information:

Vendor
Ivanti
Vendor
CVE Published:
14 January 2025

Summary

An unbounded resource search path vulnerability exists in Ivanti Endpoint Manager prior to the January-2025 Security Update. This flaw enables a remote authenticated attacker, possessing admin privileges, to execute arbitrary code on the system, potentially compromising the integrity and confidentiality of sensitive information. It is vital for users to update their systems promptly to mitigate this risk.

Affected Version(s)

Endpoint Manager 2024 January-2025 Security Update

Endpoint Manager 2024 January-2025 Security Update

Endpoint Manager 2022 SU6 January-2025 Security Update

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.