Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 November security update
- <= 2022 SU6 November security update
A vulnerability exists in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows remote authenticated attackers with admin privileges to execute code by exploiting an unbounded resource search path.
Exploitation of this vulnerability leads to unauthorized remote code execution on the affected system.
Users can apply the Security Hot Patch available for their EPM version. For EPM 2024, the patch can be downloaded from the Ivanti License System (ILS) and applied to the core server and remote consoles. For EPM 2022 SU6, a similar process applies. After applying the patch, the Core Server should be rebooted.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.