ZDI-CAN-25249: ZDI-25-032: Ivanti Endpoint Manager HIIDriver Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is required if the attacker has administrative credentials to the application. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-13172.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25249?
The severity of ZDI-CAN-25249 is considered significant due to its ability to allow remote code execution.
How do I fix ZDI-CAN-25249?
To fix ZDI-CAN-25249, ensure that you update Ivanti Endpoint Manager to the latest patched version provided by Ivanti.
What are the potential impacts of ZDI-CAN-25249?
Exploitation of ZDI-CAN-25249 can lead to arbitrary code execution on affected systems.
Is user interaction necessary to exploit ZDI-CAN-25249?
Yes, user interaction is required to exploit ZDI-CAN-25249, as the target must visit a malicious site or open a harmful file.
Can ZDI-CAN-25249 affect all Ivanti Endpoint Manager installations?
ZDI-CAN-25249 can affect any Ivanti Endpoint Manager installation that is not updated to the secured version.