Description
Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate their privileges.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
2024 SU3 SR1
2022 SU8 SR2
References
forums.ivanti.com/...vanti-Endpoint-Manager-EPM-October-2025