CVE-2024-8441

MEDIUM

Ivanti EPM <2022 SU6-2024 September - Privilege Escalation

Title source: llm

Description

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

Scores

CVSS v3 6.7
EPSS 0.0066
EPSS Percentile 70.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (8)

ivanti/endpoint_manager < 2022
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager

Timeline

Published Sep 10, 2024
Tracked Since Feb 18, 2026