CVE-2024-22058: Buffer Overflow
Published May 31, 2024
·Updated
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.
Affected Software
2 affected components
Ivanti EPM<2021.1
Ivanti Endpoint Manager<=2021.1
Event History
May 31, 2024
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22058?
CVE-2024-22058 has a critical severity rating due to its potential to allow a low privilege user to execute arbitrary code with elevated permissions.
2
How do I fix CVE-2024-22058?
To fix CVE-2024-22058, upgrade to a version of Ivanti EPM newer than 2021.1 that addresses the buffer overflow vulnerability.
3
What products are affected by CVE-2024-22058?
CVE-2024-22058 affects Ivanti Endpoint Manager (EPM) versions up to and including 2021.1.
4
Who is vulnerable to CVE-2024-22058?
Local users with low privileges on machines with Ivanti EPM installed are vulnerable to CVE-2024-22058.
5
What type of vulnerability is CVE-2024-22058?
CVE-2024-22058 is a buffer overflow vulnerability that can lead to privilege escalation.