ZDI-25-032: Ivanti Endpoint Manager HIIDriver Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is required if the attacker has administrative credentials to the application. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13172.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-032?
The severity of ZDI-25-032 is high due to the potential for remote code execution.
How do I fix ZDI-25-032?
To fix ZDI-25-032, users should apply the latest security updates for Ivanti Endpoint Manager.
What products are affected by ZDI-25-032?
ZDI-25-032 affects Ivanti Endpoint Manager installations.
Does ZDI-25-032 require user interaction for exploitation?
Yes, ZDI-25-032 requires user interaction, such as visiting a malicious page or opening a malicious file.
Can ZDI-25-032 lead to arbitrary code execution?
Yes, ZDI-25-032 allows remote attackers to execute arbitrary code on affected installations.