Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 November security update
- <= 2022 SU6 November security update
A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 and 2022 SU6 releases. The vulnerability arises from an out-of-bounds write, which allows a remote unauthenticated attacker to disrupt service.
Exploitation of this vulnerability causes a denial-of-service condition, leading to service disruption.
Users can apply the January 2025 Security Update Hot Patch, available through the Ivanti License System (ILS), to address this vulnerability. After applying the patch, it's recommended to run the AgentEngineHashUpdate.exe tool to update the hash values in the database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.