Ivanti Security Update – 30 May 2024

Ivanti has released a security update to fix a vulnerability in Ivanti Endpoint Manager (EPM).

The addressed vulnerability could allow the attacker to execute arbitrary code and gain elevated privileges to the affected systems.

Ivanti Endpoint Manager (EPM) Privilege Escalation (CVE-2024-22058):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities

CVE-2024-22058

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References