Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 November security update
- <= 2022 SU6 November security update
A privilege escalation vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. This vulnerability allows a local authenticated attacker to escalate privileges by exploiting an uninitialized resource.
Exploitation of this vulnerability allows local authenticated attackers to escalate privileges, potentially leading to unauthorized access or actions within the application or system.
Users can apply the January 2025 Security Update for Ivanti Endpoint Manager 2024 or the January 2025 Security Update for Ivanti Endpoint Manager 2022 SU6. These updates are available through the Ivanti License System (ILS). After applying the patch, the 'Actions' tab in the Windows Action packages may need to be restored by installing the V2 patch, available in the ILS.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.