ZDI-25-114: Ivanti Endpoint Manager Patch Unrestricted File Upload Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is required if the attacker has administrative credentials to the application. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13171.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-114?
The severity of ZDI-25-114 is classified as critical due to its potential for remote code execution.
How do I fix ZDI-25-114?
To fix ZDI-25-114, ensure that you apply the latest security patches provided by Ivanti for the Endpoint Manager.
What systems are affected by ZDI-25-114?
ZDI-25-114 affects installations of Ivanti Endpoint Manager.
What is the attack vector for ZDI-25-114?
The attack vector for ZDI-25-114 requires user interaction, such as visiting a malicious webpage or opening a malicious file.
Can ZDI-25-114 be exploited without user interaction?
No, exploitation of ZDI-25-114 requires user interaction in its current form.