CVE-2025-11622: High severity Ivanti Endpoint Manager vulnerability
Published Oct 13, 2025
·Updated
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
Affected Software
6 affected components
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Event History
Oct 13, 2025
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11622?
CVE-2025-11622 is classified as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-11622?
To fix CVE-2025-11622, upgrade to Ivanti Endpoint Manager version 2024 or later, addressing the insecure deserialization issue.
3
Who is affected by CVE-2025-11622?
CVE-2025-11622 affects all versions of Ivanti Endpoint Manager prior to the 2024 release.
4
What types of attacks can exploit CVE-2025-11622?
CVE-2025-11622 can be exploited by local authenticated attackers to escalate their privileges.
5
Is there a workaround for CVE-2025-11622?
There is no known workaround for CVE-2025-11622; the recommended solution is to apply the appropriate software updates.