Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
affected
2024 SU1 (custom)
unaffected
2022 SU7 (custom)
unaffected
Description
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
Problem types
CWE-427 Uncontrolled Search Path Element
Product status
2024 SU1 (custom)
2022 SU7 (custom)
References
seclists.org/fulldisclosure/2025/May/17
forums.ivanti.com/...pril-2025-for-EPM-2024-and-EPM-2022-SU6