CVE-2025-22458
HIGHIvanti Endpoint Manager < 2022 - Uncontrolled Search Path
Title source: ruleDescription
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
35.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (9)
ivanti/endpoint_manager
< 2022
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
ivanti/endpoint_manager
Timeline
Published
Apr 08, 2025
Tracked Since
Feb 18, 2026