First published: Fri Sep 23 2022(Updated: )
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is a security bug that allows a limited user to get escalated admin privileges on their system.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti Endpoint Manager | <2021.1.1 | |
Ivanti Endpoint Manager | =2021.1.1 | |
Ivanti Endpoint Manager | =2021.1.1-su1 | |
Ivanti Endpoint Manager | =2021.1.1-su2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security bug is CVE-2022-30121.
The affected software is Ivanti Endpoint Manager.
Versions 2021.1.1, 2021.1.1-su1, and 2021.1.1-su2 of Ivanti Endpoint Manager are affected.
A limited user can gain escalated admin privileges on their system with this vulnerability.
The severity of CVE-2022-30121 is medium (6.7).
Yes, there is a security advisory available for this vulnerability. You can find it at: https://forums.ivanti.com/s/article/Security-Advisory-for-Ivanti-Endpoint-Manager-Client-CVE-2022-30121?language=en_US