ZDI-25-034: Ivanti Endpoint Manager AlertService Type Confusion Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Ivanti Endpoint Manager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-13169.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-034?
The severity of ZDI-25-034 is classified as medium, allowing local attackers to disclose sensitive information.
How do I fix ZDI-25-034?
To fix ZDI-25-034, update to the latest version of Ivanti Endpoint Manager that addresses this vulnerability.
Who is affected by ZDI-25-034?
Ivanti Endpoint Manager installations that allow local code execution are affected by ZDI-25-034.
What type of attack does ZDI-25-034 involve?
ZDI-25-034 involves local code execution that leads to sensitive information disclosure.
Can I exploit ZDI-25-034 remotely?
No, exploitation of ZDI-25-034 requires local access to the affected system.