PT-2025-15432 · Ivanti · Ivanti Endpoint Manager
Publicado
2025-04-08
·
Atualizado
2025-05-21
·
CVE-2025-22458
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Ivanti Endpoint Manager versions prior to 2024 SU1
Ivanti Endpoint Manager versions prior to 2022 SU7
Description:
The issue allows an authenticated attacker to escalate to System. It is related to DLL hijacking, where a SYSTEM task loads DLLs from user-writable paths, enabling local escalation and persistence.
Recommendations:
For versions prior to 2024 SU1, update to version 2024 SU1 or later.
For versions prior to 2022 SU7, update to version 2022 SU7 or later.
As a temporary workaround, consider restricting access to user-writable paths to minimize the risk of exploitation.
Correção
LPE
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ivanti Endpoint Manager