CVE-2025-22458: High severity Ivanti Endpoint Manager vulnerability
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22458?
CVE-2025-22458 is considered a high-severity vulnerability due to its potential for authentication bypass leading to system privilege escalation.
How do I fix CVE-2025-22458?
To remediate CVE-2025-22458, update Ivanti Endpoint Manager to version 2024 SU1 or version 2022 SU7 or later.
Who is affected by CVE-2025-22458?
Users of Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7 are affected by CVE-2025-22458.
What impact does CVE-2025-22458 have on my system?
CVE-2025-22458 allows an authenticated attacker to escalate privileges to system level, compromising the security of the affected system.
Is there a workaround for CVE-2025-22458 if I cannot update?
No specific workarounds are recommended for CVE-2025-22458, so updating to the patched versions is the best course of action.