Ivanti Endpoint Manager Insecure Default Permissions Vulnerability Allowing Arbitrary File Write

Vulnerability

A vulnerability exists in Ivanti Endpoint Manager versions 2024 SU3 SR1 and prior, due to insecure default permissions in the agent. This vulnerability allows local authenticated attackers to write arbitrary files anywhere on the disk.

Impact

Exploitation of this vulnerability could lead to unauthorized file modifications, potentially allowing for further exploitation or disruption of the system.

Remediation

Users can upgrade to Ivanti Endpoint Manager 2024 SU4 to address this vulnerability. The update is available for download through the Ivanti License System.

Added: Nov 11, 2025, 4:35 PM
Updated: Nov 11, 2025, 4:35 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.