First published: Thu Nov 12 2020(Updated: )
Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service account having SeImpersonatePrivilege (eg. user ‘NT AUTHORITY\NETWORK SERVICE’).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager | <=2020.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13770 is a vulnerability in Ivanti Endpoint Manager that allows privilege escalation from a local standard or service account.
CVE-2020-13770 has a severity score of 7.8 (High).
Ivanti Endpoint Manager versions up to and including 2020.1.1 are affected by CVE-2020-13770.
CVE-2020-13770 can be exploited by accessing named pipes in Ivanti Endpoint Manager with default or overly permissive security attributes.
You can find more information about CVE-2020-13770 at the following link: [https://labs.jumpsec.com/advisory-cve-2020-13770-ivanti-uem-named-pipe-token-impersonation/](https://labs.jumpsec.com/advisory-cve-2020-13770-ivanti-uem-named-pipe-token-impersonation/)