CVE-2022-44569
HIGHIvanti Automation < 2023.4 - Authenticated Authentication Bypass via Insecure IPC
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-44569. PoCs published by rweijnen.
AI-analyzed exploit summary This PoC exploits CVE-2022-44569 in Ivanti Automation Manager by leveraging the 'processor.exe' utility to create a file with admin user group information, then launching the Ivanti AM console to potentially escalate privileges. The exploit relies on improper file handling and privilege checks in the Ivanti software.
Description
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
Exploits (1)
This PoC exploits CVE-2022-44569 in Ivanti Automation Manager by leveraging the 'processor.exe' utility to create a file with admin user group information, then launching the Ivanti AM console to potentially escalate privileges. The exploit relies on improper file handling and privilege checks in the Ivanti software.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H