Ivanti Endpoint Manager Out-of-Bounds Write Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions prior to the January 2025 Security Update for both the 2024 release and the 2022 SU6 release. The vulnerability arises from an out-of-bounds write, allowing a remote unauthenticated attacker to disrupt service.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, disrupting normal service operations.

Remediation

Users can apply the January 2025 Security Update for Ivanti Endpoint Manager 2024 or the January 2025 Security Update for Ivanti Endpoint Manager 2022 SU6. These updates are available through the Ivanti License System (ILS). After applying the patch, it's recommended to run 'AgentEngineHashUpdate.exe' to update the hash values in the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.