ZDI-25-040: Ivanti Endpoint Manager DecodeBase64Object Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is required if the attacker has administrative credentials to the application. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13163.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-040?
The severity of ZDI-25-040 is critical due to its potential for remote code execution.
How do I fix ZDI-25-040?
To fix ZDI-25-040, apply the latest security patches provided by Ivanti for the Endpoint Manager.
What software is affected by ZDI-25-040?
ZDI-25-040 affects Ivanti Endpoint Manager installations.
Who can exploit ZDI-25-040?
Remote attackers can exploit ZDI-25-040, but user interaction is required to trigger the vulnerability.
What are the risks of not addressing ZDI-25-040?
Not addressing ZDI-25-040 can lead to unauthorized access and arbitrary code execution, compromising system security.