CVE-2025-22458

HIGH

Ivanti Endpoint Manager < 2022 - Uncontrolled Search Path

Title source: rule

Description

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

Scores

CVSS v3 7.8
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (9)

ivanti/endpoint_manager < 2022
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager

Timeline

Published Apr 08, 2025
Tracked Since Feb 18, 2026