Untrusted Pointer Dereference Vulnerability in Ivanti Endpoint Manager
CVE-2025-22464

6.1MEDIUM

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
8 April 2025

What is CVE-2025-22464?

An untrusted pointer dereference vulnerability exists in Ivanti Endpoint Manager, affecting both the 2024 SU1 and 2022 SU7 versions. This flaw allows a local attacker to manipulate memory by writing arbitrary data, which can lead to a denial-of-service condition. It is crucial for users to upgrade to the latest versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Endpoint Manager 2024 SU1

Endpoint Manager 2024 SU1

Endpoint Manager 2022 SU7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22464 : Untrusted Pointer Dereference Vulnerability in Ivanti Endpoint Manager