Ivanti Security Update – 22 June 2023

Ivanti has released security update to address a vulnerability in Ivanti Endpoint Manager (EPM).

The addressed vulnerability could allow the unauthenticated attacker to execute arbitrary code on Ivanti EPM 2022 SU3 and all previous versions to escalate privileges on the affected machine or to be used as a stepping stone to get to other network attached machines.

EPM Remote Code Execution Vulnerability (CVE-2023-28323):

  • CVSS: 9.6
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Code Execution
Vulnerabilities

CVE-2023-28323

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References